VYPR

Oidcc

by Ninenines

hex: oidcc

Source repositories

CVEs (2)

  • CVE-2026-75759HigAug 30, 2026
    risk 0.42cvss —epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted…

  • CVE-2024-31209MedApr 4, 2024
    risk 0.27cvss 5.3epss 0.00

    oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in…