Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.5
CVE-2026-45414PATCHED
rubygems · decidim

Decidim: JWT-backed authentication can be replayed across organizations

Description

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.

Affected Products

VendorProductVersions
rubygemsdecidim< 0.31.5, >= 0.32.0.rc1, < 0.32.0.rc2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
rubygemsdecidimGHSA85%

References

  • https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q(x_refsource_CONFIRM)
  • https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1(x_refsource_MISC)
  • https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c(x_refsource_MISC)
  • https://github.com/decidim/decidim/releases/tag/v0.31.5(x_refsource_MISC)
  • https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-45414 | Decidim up to 0.31.4/0.32.0.rc1 JWT Authentication proposal.answer improper authentication
→ No new info (linked only)
CVSS 3.18.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
decidim@0.31.5decidim@0.32.0
CWECWE-639, CWE-863
PublishedJul 13, 2026
Tags
GHSA-r3v7-5x4c-c69qrubygems
Trending Score5
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 61
NONECVE-2026-61666
websocket-driver: Denial of service via malformed Host header
Trending: 8
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 7
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 6
MEDIUMCVE-2026-45415
Decidim: CSV census record endpoints improper authorization
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Patch Available
Aug 7, 2026