GHSA-frwg-xgr9-44pgMediumCVSS 5.4

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp...

Published
August 29, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor.

🔗 References (6)