VYPR

Boruta

by Malach It

CVEs (3)

  • CVE-2026-53431Jul 30, 2026
    risk 0.00cvss epss 0.00

    Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta accepts JWT-based client authentication…

  • CVE-2026-65635Jul 30, 2026
    risk 0.00cvss epss 0.00

    Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…

  • CVE-2026-54885Jul 30, 2026
    risk 0.00cvss epss 0.00

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…