-------------------------------------------------------------------------
Debian LTS Advisory DLA-4605-1                [email protected]
https://www.debian.org/lts/security/                       Emmanuel Arias
May 28, 2026                                  https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : python-flask-httpauth
Version        : 3.2.4-3.1+deb11u1
CVE ID         : CVE-2026-34531
Debian Bug     : 1132581

A vulnerability was found in python-flask-httpauth, a Flask extension that
simplifies the use of HTTP authentication with Flask routes, that in a situation
where the client makes a request to a token protected resource without passing a
token, or passing an empty token, python-flask-httpauth would invoke the
application's token verification callback function with the token argument set
to an empty string. If the application had any users in its database with an
empty string set as their token, then it could potentially authenticate the
client request against any of those users.

For Debian 11 bullseye, this problem has been fixed in version
3.2.4-3.1+deb11u1.

We recommend that you upgrade your python-flask-httpauth packages.

For the detailed security status of python-flask-httpauth please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-flask-httpauth

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to