Denial of Service Vulnerability in lmammino oidc-authorizer Product
CVE-2026-19362
6.9MEDIUM
What is CVE-2026-19362?
A vulnerability exists in lmammino oidc-authorizer version 0.4.0, specifically in the parse_token_from_header function located in src/parse_token_from_header.rs. This vulnerability can be exploited through manipulation of the authorization_token argument, potentially leading to a denial of service. The disclosure has been publicly available, and remote exploitation is possible. Attempts to notify the vendor about this issue were unsuccessful.
Affected Version(s)
oidc-authorizer 0.4.0
