Biscuitsec develops the Biscuit authentication and authorization framework, available across multiple language implementations including Go, Haskell, and Java, with a modestly represented vulnerability footprint centered on the core library and its integrations. The recurring exposure reflects the cryptographic and access-control demands of an authentication system, with observed weakness classes spanning improper privilege management, security token assignment flaws, and cryptographic signature verification issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Biscuitsec over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31053CRITICAL Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious acto | Jun 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-41949MEDIUM biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferr | Aug 1, 2024 | 6.4 | 19 | NO | NO |
CVE-2024-41948MEDIUM biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferr | Aug 1, 2024 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Biscuitsec.
Media articles that mention a CVE ID that affects a product developed by Biscuitsec — matched by CVE ID, not by vendor name.