CVE-2026-32714: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32714 is a SQL Injection vulnerability in the KeyCache class of the SciTokens Python reference library, which is used for generating and validating SciTokens in scientific computing environments. The flaw exists in all versions prior to 1.9.6, where Python's str.format() was used to construct SQL queries with user-supplied issuer and key_id values, enabling arbitrary SQL command execution against the local SQLite database. The vulnerability was published on March 31, 2026, with a patch released in version 1.9.6. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically the use of Python's str.format() to interpolate user-controlled values directly into SQL query strings in src/scitokens/utils/keycache.py. At least five vulnerable code locations were identified across the methods addkeyinfo, _addkeyinfo, _delete_cache_entry, _add_negative_cache_entry, and getkeyinfo. An attacker who can supply a malicious issuer or key_id value — for example, via a crafted JWT token or a malicious issuer endpoint — can inject SQL payloads such as any' OR '1'='1' -- to manipulate DELETE, INSERT, or SELECT operations against the SQLite key cache database. No authentication or special privileges are required, and the attack is remotely exploitable over the network (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to read, modify, or delete entries in the local SQLite key cache database, which can undermine the integrity of the token validation process. An attacker could clear the entire key cache (causing denial of service for token verification), inject malicious keys to bypass authentication, or leak cached key material. In certain SQLite configurations, more severe outcomes are possible, including potential remote code execution via SQLite's ATTACH DATABASE feature to write attacker-controlled files to the filesystem (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) Python script is publicly available in the GitHub Security Advisory, demonstrating the injection by clearing the entire keycache table using a crafted issuer value. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (4th percentile), indicating a low current probability of active exploitation (GitHub Advisory, GitHub Advisory DB).

Exploitation steps

  1. Identify a target: Locate a service or application that uses the SciTokens Python library (pip package scitokens) at a version prior to 1.9.6 and accepts externally-supplied token issuers or key IDs.
  2. Craft a malicious issuer or key_id: Prepare a SQL injection payload for the issuer or key_id field, such as any' OR '1'='1' -- (for a DELETE/SELECT bypass) or x' UNION SELECT * FROM keycache -- (for data exfiltration).
  3. Deliver the payload: Submit a crafted JWT or token to the target application with the malicious issuer claim, or interact with an endpoint that triggers KeyCache.addkeyinfo(), getkeyinfo(), _delete_cache_entry(), or _add_negative_cache_entry() with attacker-controlled input.
  4. Trigger SQL execution: The vulnerable str.format() call in keycache.py interpolates the payload directly into the SQL query string, causing the SQLite database to execute the injected command (e.g., deleting all cache entries or returning unauthorized data).
  5. Achieve objective: Depending on the payload, the attacker can wipe the key cache (disrupting token validation), inject rogue keys, exfiltrate cached key data, or — in advanced scenarios — use SQLite's ATTACH DATABASE to write files and potentially achieve code execution (GitHub Advisory).

Indicators of compromise

  • Logs: Application or library logs showing unexpected SQLite errors or exceptions from keycache.py methods (addkeyinfo, getkeyinfo, _delete_cache_entry, _add_negative_cache_entry); log entries with issuer or key_id values containing SQL metacharacters such as single quotes ('), OR, UNION, --, or DROP.
  • File System: Unexpected files written to the filesystem by the process running SciTokens (possible indicator of SQLite ATTACH DATABASE abuse); sudden emptying or corruption of the SQLite key cache database file (typically located under XDG_CACHE_HOME or a configured cache path).
  • Process Behavior: Unusual child processes spawned by the Python process running SciTokens; unexpected file creation in directories accessible to the SciTokens service account.
  • Network: Inbound requests to token validation endpoints with issuer or key_id fields containing SQL injection strings; repeated token validation failures from a single source IP (GitHub Advisory).

Mitigation and workarounds

Upgrade the SciTokens library to version 1.9.6 or later, which replaces all str.format()-based SQL construction in keycache.py with parameterized queries using SQLite's ? placeholder syntax. The fix was implemented in commit 3dba108 and includes regression tests to prevent reintroduction of the vulnerability. If immediate patching is not possible, restrict network access to applications using SciTokens and validate or sanitize all issuer and key_id inputs before they reach the library (Patch Commit, v1.9.6 Release).

Community reactions

The vulnerability was reported by researcher pmcao and remediated by djw8605 (Derek Weitzel), the SciTokens maintainer, who published the advisory and patch simultaneously. Red Hat tracked the issue as urgent severity in their Bugzilla system. Coverage appeared on security aggregation sites including The Hacker Wire and Infinitsec, and the advisory was discussed on Mastodon and Bluesky shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management