id: PYSEC-2026-1463 published: "2026-07-07T16:03:04.718927Z" modified: "2026-07-07T17:24:20.741649Z" aliases: - CVE-2025-59036 - GHSA-v2p7-4pv4-3wwh summary: "Infrahub: Deleted and expired API tokens can still authenticate" details: "### Impact\nA bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully.\n\n### Patches\nThis issue is fixed in versions `1.3.9` and `1.4.5`\n\n### Workarounds\nUsers can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating." affected: - package: name: infrahub-server ecosystem: PyPI purl: pkg:pypi/infrahub-server ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.3.9 - introduced: 1.4.0 - fixed: 1.4.5 versions: - 1.0.1 - 1.0.10 - 1.0.8 - 1.0.9 - 1.1.0 - 1.1.0b2 - 1.1.1 - 1.1.10 - 1.1.2 - 1.1.3 - 1.1.4 - 1.1.5 - 1.1.6 - 1.1.7 - 1.1.8 - 1.1.9 - 1.2.0 - 1.2.0b1 - 1.2.0rc0 - 1.2.1 - 1.2.10 - 1.2.11 - 1.2.12 - 1.2.2 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.7 - 1.2.8 - 1.2.9 - 1.2.9rc0 - 1.3.0 - 1.3.0a0 - 1.3.0b1 - 1.3.0b2 - 1.3.0b3 - 1.3.0b5 - 1.3.0b6 - 1.3.1 - 1.3.2 - 1.3.3 - 1.3.4 - 1.3.5 - 1.3.6 - 1.3.7 - 1.3.8 - 1.4.0 - 1.4.1 - 1.4.2 - 1.4.3 - 1.4.4 references: - type: WEB url: https://github.com/opsmill/infrahub/security/advisories/GHSA-v2p7-4pv4-3wwh - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-59036 - type: WEB url: https://github.com/opsmill/infrahub/commit/215185f217e2f754f7c0a0aa4b77e11079a063a1 - type: WEB url: https://github.com/opsmill/infrahub/commit/61b49a4a9e988f10c3a44f0e86ef97f344a1e228 - type: PACKAGE url: https://github.com/opsmill/infrahub - type: WEB url: https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.3.9 - type: WEB url: https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.4.5 - type: PACKAGE url: https://pypi.org/project/infrahub-server - type: ADVISORY url: https://github.com/advisories/GHSA-v2p7-4pv4-3wwh severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L