Current section

2 Advisories

Jump to
EEF-CVE-2026-75759 CVE-2026-75759 GHSA-533g-4vf3-xwrj

Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc

August 30, 2026
CVSS
?
7.6 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 3.2.0-beta.1 and < 3.9.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 1K 2K 3K 4K

this version

2 931

yesterday

2 046

last 7 days

13 475

all time

827 456

Last Updated

Aug 30, 2026

License

Apache-2.0

Build Tools

rebar3 mix

Links