Scitokens provides token-based authentication libraries for distributed computing and research infrastructure, with a narrow product scope centered on its core authentication library and a C++ variant. The observed vulnerability surface clusters around authorization and access-control weaknesses—including improper authorization checks, path traversal, and SQL injection—that reflect the authentication and credential-validation role these libraries play in protecting scientific computing resources. Current counts and detailed findings are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scitokens over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32714CRITICAL SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python' | Mar 31, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-32726HIGH SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scop | Mar 31, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-32725HIGH SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing pa | Mar 31, 2026 | 8.3 | 28 | NO | NO |
CVE-2026-32727MEDIUM SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot | Mar 31, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-32716MEDIUM SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startswi | Mar 31, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scitokens.
Media articles that mention a CVE ID that affects a product developed by Scitokens — matched by CVE ID, not by vendor name.