MEDIUM5.5
PYSEC-2026-1463
Infrahub: Deleted and expired API tokens can still authenticate
Quick fix
PYSEC-2026-1463 — infrahub-server: upgrade to the fixed version with the command below.
pip install --upgrade 'infrahub-server>=1.3.9'Details
### Impact A bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully.
### Patches This issue is fixed in versions `1.3.9` and `1.4.5`
### Workarounds Users can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/infrahub-server
Introduced in:
0Fixed in: 1.3.9Fix
pip install --upgrade 'infrahub-server>=1.3.9'References
- https://github.com/opsmill/infrahub/security/advisories/GHSA-v2p7-4pv4-3wwh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-59036[ADVISORY]
- https://github.com/opsmill/infrahub/commit/215185f217e2f754f7c0a0aa4b77e11079a063a1[WEB]
- https://github.com/opsmill/infrahub/commit/61b49a4a9e988f10c3a44f0e86ef97f344a1e228[WEB]
- https://github.com/opsmill/infrahub[PACKAGE]
- https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.3.9[WEB]
- https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.4.5[WEB]
- https://pypi.org/project/infrahub-server[PACKAGE]
- https://github.com/advisories/GHSA-v2p7-4pv4-3wwh[ADVISORY]