CVE-2026-47270: Avoid Non Reentrant Strtok

The `strtok()` function is non-reentrant and intrinsically thread-unsafe due to its use of a shared static buffer to store state. In multi-threaded contexts such as PAM modules, using `strtok()` can cause race conditions, leading to corrupted token parsing and unauthorized or denied accesses. Furthermore, `strtok()` mutates strings in-place; directly passing

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-47270-avoid-non-reentrant-strtok --engine opengrep

Description

The `strtok()` function is non-reentrant and intrinsically thread-unsafe due to its use of a shared static buffer to store state. In multi-threaded contexts such as PAM modules, using `strtok()` can cause race conditions, leading to corrupted token parsing and unauthorized or denied accesses. Furthermore, `strtok()` mutates strings in-place; directly passing