CVE-2020-10184: Yubico Yubikey One Time Password Validation Server

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.

Affected products

  • Yubico Yubikey One Time Password Validation Server: before 2.40 (fixed in 2.40)

Published 2020-03-05. Last modified 2026-06-17.