CVE-2026-28513
Last modified
CVE-2026-28513 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. This vulnerability is fixed in 2.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pocket-Id | Pocket Id | < 2.4.0 |
References
- https://github.com/pocket-id/pocket-id/security/advisories/GHSA-qh6q-598w-w6m2Exploit, Vendor Advisory
- https://github.com/pocket-id/pocket-id/security/advisories/GHSA-qh6q-598w-w6m2Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-28513?
How severe is CVE-2026-28513?
How do I fix CVE-2026-28513?
Are you affected by CVE-2026-28513?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
