VYPR

Punk Oauth2 Server

by RubyGems

CVEs (1)

  • CVE-2026-75866CriAug 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client…