Payment Status Validation Vulnerability in GiroCheckout Integration by Pretix
CVE-2026-18029

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-18029?

The payment integration with GiroCheckout in Pretix exhibits a flaw in its validation of payment status responses. This vulnerability allows an attacker to replay a successful payment status response from one transaction to obtain multiple valid tickets using only one payment, potentially leading to unauthorized access to services. Proper validation mechanisms must be implemented to ensure the integrity of transaction statuses and mitigate this risk.

Affected Version(s)

pretix-girosolution 0 < 1.0.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.