VYPR

OidcClientCodeRequestFilter

by Apache

CVEs (1)

  • CVE-2026-71575Oct 9, 2026
    risk 0.00cvss —epss —

    The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any…