VYPR

Librest

by GNOME Foundation

CVEs (2)

  • CVE-2015-2675HigAug 18, 2017
    risk 0.49cvss 7.5epss 0.03

    The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the…

  • CVE-2026-16615MedJul 22, 2026
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor…