CVE-2020-10185: Yubico Yubikey One Time Password Validation Server

High severity, CVSS 8.6. EPSS: 1.7% chance of exploitation in the next 30 days.

The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.

Affected products

  • Yubico Yubikey One Time Password Validation Server: before 2.40 (fixed in 2.40)

Published 2020-03-05. Last modified 2026-06-17.