Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-42731

25
FAUCET Score

CVE-2022-42731 is a replay attack vulnerability in django-mfa2 versions before 2.5.1 and 2.6.x before 2.6.1, specifically within the mfa/FIDO2.py component. This flaw allows an attacker to register an unauthorized device for a legitimate user because the FIDO2 device registration challenge is not invalidated after its initial use. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a network-based attack vector with low complexity, requiring no user interaction, and can lead to high integrity impact by allowing unauthorized device registration. While the EPSS score is low, indicating a low probability of exploitation, the FAUCET Risk Score is 48/100. Currently, there is no evidence of active exploitation, and no public exploit code is available for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article referencing the CVE, suggesting limited public awareness or immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.1CPE matchmatch criteria
cpe:2.3:a:django-mfa2_project:django-mfa2:*:*:*:*:*:*:*:*
>= 2.6.0, < 2.6.1CPE matchmatch criteria
cpe:2.3:a:django-mfa2_project:django-mfa2:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.03%
Probability of exploitation in next 30 days
EPSS Percentile
60.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0103 is in the 37th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: django-mfa2Fixed in: 2.5.1
pippatch availablevia ghsa
Product: django-mfa2Fixed in: 2.6.1

Vendor Advisories (1)

pipGHSA-vw39-2wj9-4q86high

django-mfa2 vulnerable to MFA Replay attack

Oct 11, 2022

References

github.com / mkalioby/django-mfa2/blob/0936ea253354dd95cb127f09d0efa31324caef27/mfa/FIDO2.py
ExploitThird Party Advisory
github.com / mkalioby/django-mfa2/releases/tag/v2.5.1-release
Release NotesThird Party Advisory
github.com / mkalioby/django-mfa2/releases/tag/v2.6.1-release
Release NotesThird Party Advisory