VYPR

AbstractOAuthDataProvider

by Apache

CVEs (1)

  • CVE-2026-50631Jun 12, 2026
    risk 0.00cvss epss

    A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by…