Deserialization Vulnerability in lmammino oidc-authorizer Product
CVE-2026-19363
6.9MEDIUM
What is CVE-2026-19363?
A critical vulnerability has been identified in the lmammino oidc-authorizer, specifically within the Fixed Message Handler component's function unwrap located in src/handler.rs. This issue arises from improper handling of the jwtClaims argument, leading to remote deserialization attacks. Malicious actors can exploit this flaw to manipulate data and potentially execute unauthorized actions on affected systems. Despite being reported to the vendor, there has been no acknowledgment or response regarding this issue, highlighting the urgency for users to assess their systems and apply necessary mitigations.
Affected Version(s)
oidc-authorizer 0.1
oidc-authorizer 0.2
oidc-authorizer 0.3
