CVE-2026-13602
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 8 assertions
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-sofort","product":"pretix-sofort","repo":"https://github.com/pretix/pretix-sofort","vendor":"pretix","versions":[{"lessThan":"1.4.2","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/6
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-payone","product":"pretix-payone","repo":"https://github.com/pretix/pretix-payone","vendor":"pretix","versions":[{"lessThan":"1.4.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/4
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-secuconnect","product":"pretix-secuconnect","repo":"https://github.com/pretix/pretix-secuconnect","vendor":"pretix","versions":[{"lessThan":"1.0.4","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/5
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-oppwa","product":"pretix-oppwa","repo":"https://github.com/pretix/pretix-oppwa","vendor":"pretix","versions":[{"lessThan":"1.4.4","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/2
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-saferpay","product":"pretix-saferpay","repo":"https://github.com/pretix/pretix-saferpay","vendor":"pretix","versions":[{"lessThan":"1.6.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/7
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-bitpay","product":"pretix-bitpay","repo":"https://github.com/pretix/pretix-bitpay","vendor":"pretix","versions":[{"lessThan":"1.5.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/3
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix","product":"pretix","repo":"https://github.com/pretix/pretix","vendor":"pretix","versions":[{"lessThan":"2026.3.5","status":"affected","version":"4.14.0","versionType":"python"},{"lessThan":"2026.4.5","status":"affected","version":"2026.4.0","versionType":"python"},{"lessThan":"2026.5.3","status":"affected","version":"2026.5.0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/0
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-mollie","product":"pretix-mollie","repo":"https://github.com/pretix/pretix-mollie","vendor":"pretix","versions":[{"lessThan":"2.5.7","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/1
cwe · 2 assertions
{"cweId":"CWE-323","description":"CWE-323 Reusing a nonce, key pair in encryption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-20","description":"CWE-20 Improper input validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
8 source assertions{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-sofort","product":"pretix-sofort","repo":"https://github.com/pretix/pretix-sofort","vendor":"pretix","versions":[{"lessThan":"1.4.2","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/6
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-payone","product":"pretix-payone","repo":"https://github.com/pretix/pretix-payone","vendor":"pretix","versions":[{"lessThan":"1.4.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/4
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-secuconnect","product":"pretix-secuconnect","repo":"https://github.com/pretix/pretix-secuconnect","vendor":"pretix","versions":[{"lessThan":"1.0.4","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/5
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-oppwa","product":"pretix-oppwa","repo":"https://github.com/pretix/pretix-oppwa","vendor":"pretix","versions":[{"lessThan":"1.4.4","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/2
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-saferpay","product":"pretix-saferpay","repo":"https://github.com/pretix/pretix-saferpay","vendor":"pretix","versions":[{"lessThan":"1.6.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/7
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-bitpay","product":"pretix-bitpay","repo":"https://github.com/pretix/pretix-bitpay","vendor":"pretix","versions":[{"lessThan":"1.5.3","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/3
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix","product":"pretix","repo":"https://github.com/pretix/pretix","vendor":"pretix","versions":[{"lessThan":"2026.3.5","status":"affected","version":"4.14.0","versionType":"python"},{"lessThan":"2026.4.5","status":"affected","version":"2026.4.0","versionType":"python"},{"lessThan":"2026.5.3","status":"affected","version":"2026.5.0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/0
{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"pretix-mollie","product":"pretix-mollie","repo":"https://github.com/pretix/pretix-mollie","vendor":"pretix","versions":[{"lessThan":"2.5.7","status":"affected","version":"0","versionType":"python"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.7,"baseSeverity":"HIGH","exploitMaturity":"UNREPORTED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-323","description":"CWE-323 Reusing a nonce, key pair in encryption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-20","description":"CWE-20 Improper input validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://pretix.eu/about/en/blog/20260701-release-2026-5-3/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8939b9b80f24966e7a40e463bf608f8d943d581399c854fc722d965b9dbe00fc · sha256:dc0e6a19fa7bedee… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.