Known Vulnerabilities for Sa-token by Dromara
Listed below are 2 of the newest known vulnerabilities associated with "Sa-token" by "Dromara".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43001 json | An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied p... | Not Provided | 2026-05-01 | 2026-05-01 |
| CVE-2026-42422 json | OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens ... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2026-42421 json | OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2026-42042 json | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token ... | Not Provided | 2026-04-24 | 2026-04-27 |
| CVE-2026-41492 json | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the ... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-41488 json | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size()... | Not Provided | 2026-04-24 | 2026-04-27 |
| CVE-2026-41356 json | OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously... | Not Provided | 2026-04-23 | 2026-04-24 |
| CVE-2026-41323 json | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, an... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-41276 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability a... | Not Provided | 2026-04-23 | 2026-04-24 |
| CVE-2026-41213 json | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-i... | Not Provided | 2026-04-23 | 2026-04-25 |