FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Rauthy -- Multiple security vulnerabilities

Affected packages
rauthy < 0.36.2

Details

VuXML ID 2ec747aa-b97e-11f1-b09d-8447094a420f
Discovery 2026-09-16
Entry 2026-09-26

The Rauthy project reports:

WebAuthn authentication code is not bound to the user. (GHSA-x8jp-v2j6-6vjf)

Refresh-token grant accepts a caller-supplied client without verifyinG it matches the token's `azp`, allowing cross-client token minting and identity/scope confusion. (https://github.com/sebadob/rauthy/security/advisories/GHSA-7qh2-3hc5-2vqp)

Unauthenticated remote panic aborts the whole process on two token endpoints (short refresh_token / device_code). (GHSA-wx92-7mmw-5x82)

References

URL https://github.com/sebadob/rauthy/security
URL https://github.com/sebadob/rauthy/security/advisories/GHSA-7qh2-3hc5-2vqp
URL https://github.com/sebadob/rauthy/security/advisories/GHSA-wx92-7mmw-5x82
URL https://github.com/sebadob/rauthy/security/advisories/GHSA-x8jp-v2j6-6vjf