Loading market data...
← Back to CVE feed

CVE-2026-18029

UNKNOWN View on NVD ↗

Description

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Published: Jul 28, 2026 11:17 UTC Modified: Jul 28, 2026 13:17 UTC