The Spnego Http Authentication Module Project maintains a narrowly scoped authentication handler that integrates SPNEGO-based authentication into HTTP servers, with the durable vulnerability signal centered on the authentication mechanism itself. Observed weaknesses focus on improper authentication implementation, reflecting the complexity of negotiating and validating SPNEGO credentials in a web context; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spnego Http Authentication Module Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21335CRITICAL In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affect | Mar 8, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spnego Http Authentication Module Project.
Media articles that mention a CVE ID that affects a product developed by Spnego Http Authentication Module Project — matched by CVE ID, not by vendor name.