CVE-2025-68402Patch

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently being called with a constructed string (SHA-256 nonce + part of a bcrypt hash) instead of the raw user password. Due to bcrypt’s 72-byte input truncation, this causes password verification to succeed even when the user enters an incorrect password. This vulnerability is fixed in 1.27.2-dev (476e57b). The issue was only present in the edge branch and never in a stable release.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-09); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-10: 103-0903-10
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-091
Patch1
2026-03-101
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-68402 FreshRSS Authentication Bypass via Improper Password Verification Mechan... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-68402 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE‑2025‑68402 as an authentication bypass vulnerability and shares a link to official vulnerability details, but it does not provide evidence of exploitation, patches, or a PoC.

    0000078
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-68402 FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently bei… https://www.cve.org/CVERecord?id=CVE-2025-68402

    Post summary

    A brief note indicates FreshRSS changed the nonce length from 40 to 64 characters, likely to address CVE‑2025‑68402, but no PoC, exploit, or detailed vulnerability information is provided.

    0000088
    56.6K followersView on X

Explore more