Known Vulnerabilities for Oidc Op by Shibboleth
Listed below are 1 of the newest known vulnerabilities associated with "Oidc Op" by "Shibboleth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73419 json | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js s... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73302 json | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passpor... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-72561 json | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-admini... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-67333 json | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67330 json | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-bet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-65583 json | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-63094 json | SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated atta... | Not Provided | 2026-07-17 | 2026-07-27 |
| CVE-2026-59819 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /hea... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59713 json | Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without vali... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-59096 json | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from ... | Not Provided | 2026-07-02 | 2026-07-14 |