GHSA-q4xf-7fw5-4x8v moderate
Laravel Hijacked authentication cookies vulnerability
Affected range
ECOSYSTEM: introduced 4.0.0; fixed 4.1.26>=4.0.0,<4.0.99|>=4.1.0,<4.1.26Fixed versions: 4.1.26
The Illuminate Auth package.
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
13.32.0
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Moderate
3 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 4.0.0; fixed 4.1.26>=4.0.0,<4.0.99|>=4.1.0,<4.1.26Fixed versions: 4.1.26
Affected range
ECOSYSTEM: introduced 5.3.0; last affected 5.3.31ECOSYSTEM: introduced 5.4.0; fixed 5.4.22>=5.3.0,<=5.3.31|>=5.4.0,<5.4.22Fixed versions: 5.4.22
Affected range
ECOSYSTEM: introduced 0; fixed 5.5.10>=4.1.26,<=4.1.31|>=4.2.0,<=4.2.22|>=5.0.0,<=5.0.35|>=5.1.0,<=5.1.46|>=5.2.0,<=5.2.45|>=5.3.0,<=5.3.31|>=5.4.0,<=5.4.36|>=5.5.0,<5.5.10Fixed versions: 5.5.10