#1146126 ruby-rodauth: CVE-2026-82467 CVE-2026-82468 CVE-2026-82469 CVE-2026-82470

Package:
src:ruby-rodauth
Source:
src:ruby-rodauth
Submitter:
Salvatore Bonaccorso
Date:
2026-09-08 15:37:03 UTC
Severity:
normal
Tags:
#1146126#5
Date:
2026-08-30 07:11:21 UTC
From:
To:
Hi,

The following vulnerabilities were published for ruby-rodauth.

CVE-2026-82467[0]:
| Rodauth before 2.47.0 fails to validate protocol-relative return-to
| paths in confirm_password, login_return_to_requested_location, and
| two_factor_auth_return_to_requested_location features. Attackers can
| craft paths with leading double slashes that browsers resolve as
| protocol-relative URLs, redirecting authenticated users to attacker-
| controlled sites after login or password confirmation.


CVE-2026-82468[1]:
| Rodauth before 2.47.0 contains a cross-site request forgery
| protection bypass vulnerability in the JSON request content type
| validation. Attackers can craft cross-origin form posts with content
| types containing application/json substrings to bypass CSRF token
| validation and force victims to authenticate to attacker-controlled
| accounts.


CVE-2026-82469[2]:
| Rodauth before 2.47.0 contains an authentication bypass
| vulnerability in the jwt_refresh route that issues new JWT access
| tokens without requiring a refresh token. Attackers can present an
| access token to the refresh route via non-POST methods to obtain a
| new valid access token, enabling indefinite account access with
| temporary token possession.


CVE-2026-82470[3]:
| Rodauth before 2.47.0 contains a time-based one-time password reuse
| vulnerability in the otp feature that fails to track the last
| accepted code timestamp. Attackers who observe a valid TOTP code can
| replay it during the drift window to bypass the second
| authentication factor.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-82467
https://www.cve.org/CVERecord?id=CVE-2026-82467
[1] https://security-tracker.debian.org/tracker/CVE-2026-82468
https://www.cve.org/CVERecord?id=CVE-2026-82468
[2] https://security-tracker.debian.org/tracker/CVE-2026-82469
https://www.cve.org/CVERecord?id=CVE-2026-82469
[3] https://security-tracker.debian.org/tracker/CVE-2026-82470
https://www.cve.org/CVERecord?id=CVE-2026-82470

Regards,
Salvatore

#1146126#10
Date:
2026-09-08 15:34:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ruby-rodauth, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146126@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Quigley <tsimonq2@debian.org> (supplier of updated ruby-rodauth package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 08 Sep 2026 10:29:36 -0500
Source: ruby-rodauth
Architecture: source
Version: 2.47.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Simon Quigley <tsimonq2@debian.org>
Closes: 1146126
Changes:
 ruby-rodauth (2.47.0-1) unstable; urgency=medium
 .
   * New upstream release (Closes: #1146126):
     - Fixes CVE-2026-82467, CVE-2026-82468, CVE-2026-82469, CVE-2026-82470.
Checksums-Sha1:
 7a4e3ff37eff620b74a6adfc19afdf8f89722d84 2054 ruby-rodauth_2.47.0-1.dsc
 4b9c245170c772e9b7fd97a530e3f8ad04aa2394 435823 ruby-rodauth_2.47.0.orig.tar.gz
 7a8fadce3808c6745865175dcd50a6c6556b0adf 2756 ruby-rodauth_2.47.0-1.debian.tar.xz
 cfbd38c9396245516d633902d85a21f90500ba6b 7528 ruby-rodauth_2.47.0-1_source.buildinfo
Checksums-Sha256:
 deb7c4053315f15a760d9fd10e31c09f2809e69fda9b8e01608fbdc05283a56b 2054 ruby-rodauth_2.47.0-1.dsc
 66dcf10c2bb955d938cdb09b17f4446ea9956546494ad814d932761548e27731 435823 ruby-rodauth_2.47.0.orig.tar.gz
 f81744ca31e687ad217bf52dd569ea6a65ec04f0cdd5c32b8dfd872c3a84ff8e 2756 ruby-rodauth_2.47.0-1.debian.tar.xz
 a75e6aab7e25a5ea02dd8902862505a8dedec9b7970c8972f6d2551d9ccd368f 7528 ruby-rodauth_2.47.0-1_source.buildinfo
Files:
 32bfdb4b1d80297952b231609ab4440d 2054 ruby optional ruby-rodauth_2.47.0-1.dsc
 ffb944fbccc95a6f1a9128a3ec572178 435823 ruby optional ruby-rodauth_2.47.0.orig.tar.gz
 25498543654ab57556856e78547f7fa2 2756 ruby optional ruby-rodauth_2.47.0-1.debian.tar.xz
 acd256cfe229a548323a9a8ab933a20b 7528 ruby optional ruby-rodauth_2.47.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmqgKf4ACgkQ4n8s+EWM
L6TJ4w//WPxFdwy2OcN4bfuDRR35tzmbsR2iO0yiQLZ9vI2BiM5/chHxqMeFqIxC
MJbbuzxbs5IZE/nCtBvYFOQYV7IhK8klq2TULN7blFs4GdAt+FRsVKliFQChrq+D
gZDlVAfFOAwMTSWbq1mTD0JJBn4zSztaUe9nVMBTQRBIIuZoeb8EWFJG4YgcGEYF
deO/DGzMxQiUQbhht8nxE7N5A2EE6UomNOi5p2248ktMVvHuGMwzgR8s1djqT7KM
QoKGAcsUMQCohJ+JhhK46ot6g0734HME8VZ+3IJlgEQ9HyvfrSzcu78YNOata04E
AJG0LBuGtco8wI8AhAuN59czK8Xowq6dhmQnbH62SfHf8iZerTPWGirIi2eSzQQN
FfvYEuSt2OEFzUemjC4GLQ8I2FgZTyy81lyp7Q2+A0a/HidWwdFvAVAky/ADGbbi
v0dy71qg5HNKVLWQuoDUuG19KzBazsSCS8syaSjpZ8r96t1kzubtwSc0Jj8Qmjeh
Oik8Qulp8kfqeXoS2PnZFsV+u1elwquiHPIXL6n374lhCPHKsPD9Bn7+IBAkWFLl
So2OpcRUB43GymklcXbUb4DebN70bsT7HukUJr3oy0EDb5yf764qLD8YjZcj9SHE
9GuConznBBSeQjzL5WUzKjNv7m70nNbe5vu4rN0e2YlGHSUprOg=
=WKuT
-----END PGP SIGNATURE-----