← Back to CVEs
CVE-2026-5774
N/ADescription
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
CVE Details
CVSS v3.1 ScoreN/A
Published4/10/2026
Last Modified4/13/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-362
References
https://github.com/juju/juju/pull/22205(security@ubuntu.com)
https://github.com/juju/juju/pull/22206(security@ubuntu.com)
https://github.com/juju/juju/security/advisories/GHSA-7m55-2hr4-pw78(security@ubuntu.com)
https://github.com/juju/juju/security/advisories/GHSA-7m55-2hr4-pw78(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.