oidcc
OpenID Connect client library for the BEAM.
Activity
- Latest release
- 2w ago
- Total releases
- 57
- Cadence
- ~9 days
- Last 12 months
- 6
Reach
- Downloads
- 814.9k
Details
- License
- Apache-2.0
- First release
- Jan 27, 2017
| Version | Released | |
|---|---|---|
3.9.0
minor
|
3.9.0
minor
Dependencies (4)
|
|
3.8.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.8.0
minor
Dependencies (4)
|
|
3.8.0-beta.1
pre
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.8.0-beta.1
pre
Dependencies (4)
|
|
3.7.2
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.7.2
patch
Dependencies (4)
|
|
3.7.1
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.7.1
patch
Dependencies (4)
|
|
3.7.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.7.0
minor
Dependencies (4)
|
|
3.6.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.6.0
minor
Dependencies (4)
|
|
3.5.2
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.5.2
patch
Dependencies (4)
|
|
3.5.1
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.5.1
patch
Dependencies (4)
|
|
3.5.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.5.0
minor
Dependencies (4)
|
|
3.4.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.4.0
minor
Dependencies (3)
|
|
3.3.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (3)
|
|
3.2.6
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.6
patch
Dependencies (3)
|
|
3.2.5
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.5
patch
Dependencies (3)
|
|
3.2.4
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.4
patch
Dependencies (3)
|
|
3.2.3
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.3
patch
Dependencies (3)
|
|
3.2.2
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (3)
|
|
3.2.1
patch
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (3)
|
|
3.2.0
minor
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (3)
|
|
3.0.2
patch
|
3.0.2
patch
Dependencies (3)
|
|
3.1.2
patch
|
3.1.2
patch
Dependencies (3)
|
|
3.2.0-beta.3
pre
1 CVE
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev |
3.2.0-beta.3
pre
Dependencies (3)
|
|
3.2.0-beta.2
pre
2 CVEs
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.2.0-beta.2
pre
Dependencies (3)
|
|
3.2.0-beta.1
pre
2 CVEs
CVE-2026-75759
EEF-CVE-2026-75759
GHSA-533g-4vf3-xwrj
Aug 30, 2026
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Critical
Network
Low
None
SummaryImproper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. In This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0. ConfigurationsReachable only when the OpenID Provider advertises ID token encryption ( Affected versions
3.2.0
3.2.0-beta.1
3.2.0-beta.2
3.2.0-beta.3
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.3.0
3.4.0
+ 9 more Show less
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.8.0
3.8.0-beta.1
Fixed in
3.9.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.2.0-beta.1
pre
Dependencies (3)
|
|
3.1.2-beta.1
pre
1 CVE
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.1.2-beta.1
pre
Dependencies (3)
|
|
3.1.1
patch
1 CVE
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.1.1
patch
Dependencies (3)
|
|
3.1.0
minor
1 CVE
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.1.0
minor
Dependencies (3)
|
|
3.1.0-beta.2
pre
|
3.1.0-beta.2
pre
Dependencies (3)
|
|
3.1.0-beta.1
pre
|
3.1.0-beta.1
pre
Dependencies (3)
|
|
3.0.1
patch
1 CVE
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.0.1
patch
Dependencies (3)
|
|
3.0.0
major
1 CVE
CVE-2024-31209
GHSA-mj35-2rgf-cv8p
Apr 03, 2024
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
5.3
/ 10
Medium
Local
High
High
None
Changed
None
None
High
ImpactDOS by Atom exhaustion is possible by calling Since the name is usually provided as a static value in the application using DetailsExample to illustrate the vulnerability.
The vulnerability is present in https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388 There might be a case (Very highly improbable) where the 2nd argument of
PatchesPatched in WorkaroundsMake sure only valid provider configuration worker names are passed to the functions. References
Affected versions
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2-beta.1
3.2.0-beta.1
3.2.0-beta.2
Fixed in
3.0.2
3.1.2
3.2.0-beta.3
References
Updated Dec 10, 2025 · Source: OSV.dev |
3.0.0
major
Dependencies (3)
|
|
3.0.0-rc.6
pre
|
3.0.0-rc.6
pre
Dependencies (3)
|
|
3.0.0-rc.5
pre
|
3.0.0-rc.5
pre
Dependencies (3)
|
|
3.0.0-rc.4
pre
|
3.0.0-rc.4
pre
Dependencies (3)
|
|
3.0.0-rc.3
pre
|
3.0.0-rc.3
pre
Dependencies (3)
|
|
3.0.0-rc.2
pre
|
3.0.0-rc.2
pre
Dependencies (3)
|
|
3.0.0-rc.1
pre
|
3.0.0-rc.1
pre
Dependencies (3)
|
|
3.0.0-alpha.5
pre
|
3.0.0-alpha.5
pre
Dependencies (3)
|
|
3.0.0-alpha.4
pre
|
3.0.0-alpha.4
pre
Dependencies (3)
|
|
3.0.0-alpha.3
pre
|
3.0.0-alpha.3
pre
Dependencies (3)
|
|
3.0.0-alpha.2
pre
|
3.0.0-alpha.2
pre
Dependencies (3)
|
|
3.0.0-alpha.1
pre
|
3.0.0-alpha.1
pre
Dependencies (3)
|
|
2.0.0-alpha.2
pre
|
2.0.0-alpha.2
pre
Dependencies (2)
|
|
2.0.0-alpha.1
pre
|
2.0.0-alpha.1
pre
Dependencies (2)
|
|
1.8.1
patch
|
1.8.1
patch
Dependencies (2)
|
|
1.8.0
minor
|
1.8.0
minor
Dependencies (1)
|
|
1.7.0
minor
|
1.7.0
minor
Dependencies (1)
|
|
1.6.0
minor
|
1.6.0
minor
Dependencies (1)
|
|
1.5.1
patch
|
1.5.1
patch
Dependencies (1)
|
|
1.5.0
minor
|
1.5.0
minor
Dependencies (1)
|