Skip to content

OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay

High severity GitHub Reviewed Published Mar 1, 2026 in OneUptime/oneuptime • Updated Mar 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts