Payment Status Validation Vulnerability in GiroCheckout Integration by Pretix
CVE-2026-18029
6.3MEDIUM
What is CVE-2026-18029?
The payment integration with GiroCheckout in Pretix exhibits a flaw in its validation of payment status responses. This vulnerability allows an attacker to replay a successful payment status response from one transaction to obtain multiple valid tickets using only one payment, potentially leading to unauthorized access to services. Proper validation mechanisms must be implemented to ensure the integrity of transaction statuses and mitigate this risk.
Affected Version(s)
pretix-girosolution 0 < 1.0.1
