
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32714 is a SQL Injection vulnerability in the KeyCache class of the SciTokens Python reference library, which is used for generating and validating SciTokens in scientific computing environments. The flaw exists in all versions prior to 1.9.6, where Python's str.format() was used to construct SQL queries with user-supplied issuer and key_id values, enabling arbitrary SQL command execution against the local SQLite database. The vulnerability was published on March 31, 2026, with a patch released in version 1.9.6. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Red Hat Bugzilla).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically the use of Python's str.format() to interpolate user-controlled values directly into SQL query strings in src/scitokens/utils/keycache.py. At least five vulnerable code locations were identified across the methods addkeyinfo, _addkeyinfo, _delete_cache_entry, _add_negative_cache_entry, and getkeyinfo. An attacker who can supply a malicious issuer or key_id value — for example, via a crafted JWT token or a malicious issuer endpoint — can inject SQL payloads such as any' OR '1'='1' -- to manipulate DELETE, INSERT, or SELECT operations against the SQLite key cache database. No authentication or special privileges are required, and the attack is remotely exploitable over the network (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to read, modify, or delete entries in the local SQLite key cache database, which can undermine the integrity of the token validation process. An attacker could clear the entire key cache (causing denial of service for token verification), inject malicious keys to bypass authentication, or leak cached key material. In certain SQLite configurations, more severe outcomes are possible, including potential remote code execution via SQLite's ATTACH DATABASE feature to write attacker-controlled files to the filesystem (GitHub Advisory).
A proof-of-concept (PoC) Python script is publicly available in the GitHub Security Advisory, demonstrating the injection by clearing the entire keycache table using a crafted issuer value. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (4th percentile), indicating a low current probability of active exploitation (GitHub Advisory, GitHub Advisory DB).
scitokens) at a version prior to 1.9.6 and accepts externally-supplied token issuers or key IDs.issuer or key_id field, such as any' OR '1'='1' -- (for a DELETE/SELECT bypass) or x' UNION SELECT * FROM keycache -- (for data exfiltration).issuer claim, or interact with an endpoint that triggers KeyCache.addkeyinfo(), getkeyinfo(), _delete_cache_entry(), or _add_negative_cache_entry() with attacker-controlled input.str.format() call in keycache.py interpolates the payload directly into the SQL query string, causing the SQLite database to execute the injected command (e.g., deleting all cache entries or returning unauthorized data).ATTACH DATABASE to write files and potentially achieve code execution (GitHub Advisory).keycache.py methods (addkeyinfo, getkeyinfo, _delete_cache_entry, _add_negative_cache_entry); log entries with issuer or key_id values containing SQL metacharacters such as single quotes ('), OR, UNION, --, or DROP.ATTACH DATABASE abuse); sudden emptying or corruption of the SQLite key cache database file (typically located under XDG_CACHE_HOME or a configured cache path).issuer or key_id fields containing SQL injection strings; repeated token validation failures from a single source IP (GitHub Advisory).Upgrade the SciTokens library to version 1.9.6 or later, which replaces all str.format()-based SQL construction in keycache.py with parameterized queries using SQLite's ? placeholder syntax. The fix was implemented in commit 3dba108 and includes regression tests to prevent reintroduction of the vulnerability. If immediate patching is not possible, restrict network access to applications using SciTokens and validate or sanitize all issuer and key_id inputs before they reach the library (Patch Commit, v1.9.6 Release).
The vulnerability was reported by researcher pmcao and remediated by djw8605 (Derek Weitzel), the SciTokens maintainer, who published the advisory and patch simultaneously. Red Hat tracked the issue as urgent severity in their Bugzilla system. Coverage appeared on security aggregation sites including The Hacker Wire and Infinitsec, and the advisory was discussed on Mastodon and Bluesky shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."