boruta
2.3.7
Core of an OAuth/OpenID Connect provider enabling authorization in your applications.
Current section
3 Advisories
Jump to
Current section
3 Advisories
Boruta accepts expired JWT client assertions due to missing exp claim validation
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-53431.html
- https://github.com/malach-it/boruta_auth/commit/5204f88f9b2cdd9637a755337ed5f99185be5474
- https://github.com/malach-it/boruta_auth/commit/69363432aa36760fc5438e4e17115d0f7c1b925a
- https://github.com/malach-it/boruta_auth/security/advisories/GHSA-xjv8-vmh5-xhf6
- https://hex.pm/packages/boruta
Boruta dynamic client registration allows creation of over-privileged OAuth clients
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-65635.html
- https://github.com/malach-it/boruta_auth/commit/82584c854a332482232fd25301ab12a835f9f643
- https://github.com/malach-it/boruta_auth/commit/95619a1beaff68fa766cca9b388e7c780d182525
- https://github.com/malach-it/boruta_auth/security/advisories/GHSA-w869-fcf2-68vp
- https://hex.pm/packages/boruta
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-54885.html
- https://github.com/malach-it/boruta_auth/commit/001e3dc5c259e67c6f907e98867eda4141c96d0d
- https://github.com/malach-it/boruta_auth/commit/95fb10b78129355e475681f324c9a01ef0af2be5
- https://github.com/malach-it/boruta_auth/security/advisories/GHSA-5q9h-vf5j-fr2g
- https://hex.pm/packages/boruta