Critical
Low
Medium

CVE-2025-35433

Overview

CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.

Critical
Low
Medium
No items found.

Package:

Impact:

Fix:

Year:

CVSS:

Severity:

Affected Components

Location

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo