← CVEs and Advisories

CVE-2026-40585

blueprintue/blueprintue-self-hosted-edition · Severity High (CVSS 7.4) · Discovered by Pavan Nallamothu

Password-reset tokens never expired, so a leaked or intercepted reset link stayed usable indefinitely.

Summary

Password-reset tokens have no expiry window.

References

cve.org record · GitHub Security Advisory GHSA-qr65-6vp8-whjf