CVE-2017-14775: Laravel
Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
Affected products
- Laravel Laravel: up to and including 5.5.9
Published 2017-09-28. Last modified 2026-06-17.