Current section

2 Advisories

Jump to
EEF-CVE-2026-66883 CVE-2026-66883 GHSA-w5r8-m75h-98fc

Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup

August 04, 2026
CVSS
?
6.3 / 10.0 Medium
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.1.0-alpha.3 and < 0.5.0
EEF-CVE-2026-66884 CVE-2026-66884 GHSA-fg66-w5gp-22cr

Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection

August 04, 2026
CVSS
?
2.1 / 10.0 Low
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0-beta.1 and < 0.5.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 100 200 300 400

this version

1 295

yesterday

389

last 7 days

2 518

all time

169 233

Last Updated

Aug 04, 2026

License

Apache-2.0

Build Tools

mix

Links