Skip to content

Conversation

@DeadManOfficial
Copy link

Summary

  • Added CWE-306 (Missing Authentication for Critical Function) and CWE-287 (Improper Authentication) to the cwe_ids field

Details

The advisory summary for CVE-2026-1709 (Keylime registrar mTLS bypass) references both Missing Authentication for Critical Function and Improper Authentication, but the cwe_ids array was empty. This PR adds the correct CWE mappings.

The advisory summary references Missing Authentication for Critical
Function (CWE-306) and Improper Authentication (CWE-287) but the
cwe_ids field was empty. Added both CWEs to match the described
vulnerability.
@github-actions github-actions bot changed the base branch from main to DeadManOfficial/advisory-improvement-6808 February 8, 2026 04:45
@yhidad31
Copy link

yhidad31 commented Feb 9, 2026

Hi @DeadManOfficial! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@yhidad31 yhidad31 closed this Feb 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants