CWE-305
CWE-305 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-305, highest CVSS first.
- MEDIUM 6.5CVE-2026-88837
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
- MEDIUM 4.6CVE-2026-59563public PoC
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. …
- UNSCOREDCVE-2026-85500public PoC
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides wh…