oidcc_plug
Plug Integration for the oidcc OpenID Connect Library
Activity
- Latest release
- 1mo ago
- Total releases
- 19
- Cadence
- ~19 days
- Last 12 months
- 3
Reach
- Downloads
- 165.2k
Details
- License
- Apache-2.0
- First release
- Sep 11, 2023
| Version | Released | |
|---|---|---|
0.5.1
patch
|
0.5.1
patch
Dependencies (3)
|
|
0.5.0
minor
|
0.5.0
minor
Dependencies (3)
|
|
0.4.0
minor
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.4.0
minor
Dependencies (3)
|
|
0.3.2
patch
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.3.2
patch
Dependencies (3)
|
|
0.3.1
patch
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.3.1
patch
Dependencies (3)
|
|
0.3.0
minor
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.3.0
minor
Dependencies (3)
|
|
0.2.2
patch
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.2
patch
Dependencies (2)
|
|
0.2.1
patch
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.1
patch
Dependencies (2)
|
|
0.2.0
minor
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.0
minor
Dependencies (2)
|
|
0.2.0-beta.1
pre
2 CVEs
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-66884
EEF-CVE-2026-66884
GHSA-fg66-w5gp-22cr
Aug 04, 2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Medium
Network
Low
None
SummaryCross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program file A callback request that carries no An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0. WorkaroundsInsert a plug before Affected versions
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.2.0-beta.1
pre
Dependencies (2)
|
|
0.1.2
patch
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.2
patch
Dependencies (2)
|
|
0.1.1
patch
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.1
patch
Dependencies (2)
|
|
0.1.0
initial
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0
initial
Dependencies (2)
|
|
0.1.0-rc.2
pre
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0-rc.2
pre
Dependencies (2)
|
|
0.1.0-rc.1
pre
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0-rc.1
pre
Dependencies (2)
|
|
0.1.0-alpha.4
pre
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0-alpha.4
pre
Dependencies (2)
|
|
0.1.0-alpha.3
pre
1 CVE
CVE-2026-66883
EEF-CVE-2026-66883
GHSA-w5r8-m75h-98fc
Aug 04, 2026
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Medium
Network
High
None
None
SummaryImproper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug ( This vulnerability is associated with program files
The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0. Affected versions
0.1.0
0.1.0-alpha.3
0.1.0-alpha.4
0.1.0-rc.1
0.1.0-rc.2
0.1.1
0.1.2
0.2.0
0.2.0-beta.1
0.2.1
0.2.2
0.3.0
+ 3 more Show less
0.3.1
0.3.2
0.4.0
Fixed in
0.5.0
References Updated Sep 08, 2026 · Source: OSV.dev |
0.1.0-alpha.3
pre
Dependencies (2)
|
|
0.1.0-alpha.2
pre
|
0.1.0-alpha.2
pre
Dependencies (2)
|
|
0.1.0-alpha.1
pre
|
0.1.0-alpha.1
pre
Dependencies (2)
|