Hello maintainers,
I am opening this issue to establish vendor contact for a security review of FastAPI-template. The local report identifies the following potential security findings:
- CRITICAL - JWT tokens never expire
- CRITICAL - JWT signing secret defaults to empty string
- HIGH - Data endpoints require no authentication
- HIGH - Unauthenticated Redis read/write access
- HIGH - Unauthenticated RabbitMQ/Kafka message injection
- HIGH - No rate limiting on authentication endpoints
- MEDIUM - Database credentials default to project name
- MEDIUM - GraphiQL unconditionally enabled in production
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz
Hello maintainers,
I am opening this issue to establish vendor contact for a security review of FastAPI-template. The local report identifies the following potential security findings:
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz