Known Vulnerabilities for Passport by Digi
Listed below are 3 of the newest known vulnerabilities associated with "Passport" by "Digi".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89043 json | passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and asse... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-89042 json | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing att... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-86762 json | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86755 json | Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELE... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86754 json | Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated us... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-73302 json | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passpor... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-56278 json | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56271 json | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_t... | Not Provided | 2026-07-12 | 2026-07-13 |
| CVE-2026-44756 json | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, a... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2023-4299 json | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connec... | 8.1 - HIGH | 2023-08-31 | 2023-09-06 |