WhisperX tag archive

#authentication-vulnerability

This page collects WhisperX intelligence signals tagged #authentication-vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-05-01 03:54:06 · GitHub Issues

1. HCAdmin Authentication Flaws Expose PG+ to Brute-Force Attacks Prior to Version 2026.1.1

A newly disclosed security advisory identifies two authentication vulnerabilities in HCAdmin, a component of the PG+ platform, affecting all versions prior to 2026.1.1. The flaws, rated High severity, expose systems to potential brute-force attacks and improper privilege assignment during login sequences, prompting urg...

The Lab · 2026-05-11 13:10:30 · Mastodon:mastodon.social:#infosec

2. CVE-2025-10470: Magic Link Authentication Flaw Enables Denial-of-Service via Uncontrolled Memory Growth

A high-severity vulnerability has been identified in Magic Link authentication implementations, exposing systems to potential denial-of-service conditions through uncontrolled memory consumption. Assigned CVE-2025-10470 with a CVSS score of 8.6, the flaw stems from the authentication flow accepting multiple invalid req...