MEDIUM 6.2 PyPI

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

GHSA-vcf3-26xf-fw4m · CVE-2025-62349 · PYSEC-2026-1902

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

Ready to move

Start Securing

Free, no credit card | First findings in minutes