CVE-2026-32714 | SciTokens up to 1.9.5 str.format sql injection (GHSA-rh5m-2482-966c)
A vulnerability categorized as critical has been discovered in SciTokens up to 1.9.5. The impacted element is the function str.format. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-32714. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.