VYPR

ueberauth_apple

by Ueberauth

CVEs (1)

  • CVE-2026-55954Jul 14, 2026
    risk 0.00cvss epss 0.00

    Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not…