CVE-2026-28512
Last modified
CVE-2026-28512 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick a user into opening a malicious authorization link, the authorization code may be redirected to an attacker-controlled host. This vulnerability is fixed in 2.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pocket-Id | Pocket Id | >= 2.0.0, < 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-28512?
How severe is CVE-2026-28512?
How do I fix CVE-2026-28512?
Are you affected by CVE-2026-28512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
