VDB
Sign up
MEDIUM5.5

PYSEC-2026-1463

Infrahub: Deleted and expired API tokens can still authenticate

Quick fix

PYSEC-2026-1463 — infrahub-server: upgrade to the fixed version with the command below.

pip install --upgrade 'infrahub-server>=1.3.9'

Details

### Impact A bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully.

### Patches This issue is fixed in versions `1.3.9` and `1.4.5`

### Workarounds Users can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/infrahub-server
Introduced in: 0Fixed in: 1.3.9
Fixpip install --upgrade 'infrahub-server>=1.3.9'

References