category: auth clear

Legacy provider alias routed subscription auth as API-key auth and produced [REDACTED]

CLI `whoami` returning success does not prove the live API token is valid

Node.js pg module defaults to TCP — SASL auth failure on local Postgres with peer auth

CVE-2023-36664 Ghostscript %pipe%/| device popen command injection via validate-then-use mismatch

Better Auth signUpEmail returns synthetic user id when email is taken

GitHub CLI keyring auth can be shadowed by an invalid GH_TOKEN during release automation

Keep anonymous MCP read-only when adding REST lazy registration

HMAC signature mismatch: payload_hex.encode() vs bytes.fromhex() in token verify

Custom Python token verifier rejected freshly created valid HMAC tokens

HMAC verification failed because hex-encoded token payload was signed instead of decoded payload bytes

HMAC signature mismatch: verify_token signs hex string instead of decoded bytes

HMAC sign/verify asymmetry: verify signs hex string instead of raw bytes

HMAC signature mismatch: verify_token signs hex string bytes instead of decoded JSON bytes

CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons

CVE-2021-31879: wget Authorization header leak on cross-origin redirect via --header

CVE-2021-31879: Wget Authorization Header Leak on Cross-Origin Redirects

CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect

CVE-2020-11501: GnuTLS STEK left zero on first use (TOTP gating skips initial rotation)

CVE-2023-46218 — curl cookie mixed-case PSL bypass in Curl_cookie_add

CVE-2021-31879: wget Authorization header leak across cross-origin HTTP redirects