Deserialization Vulnerability in lmammino oidc-authorizer Product
CVE-2026-19363

6.9MEDIUM

Key Information:

Vendor

Lmammino

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19363?

A critical vulnerability has been identified in the lmammino oidc-authorizer, specifically within the Fixed Message Handler component's function unwrap located in src/handler.rs. This issue arises from improper handling of the jwtClaims argument, leading to remote deserialization attacks. Malicious actors can exploit this flaw to manipulate data and potentially execute unauthorized actions on affected systems. Despite being reported to the vendor, there has been no acknowledgment or response regarding this issue, highlighting the urgency for users to assess their systems and apply necessary mitigations.

Affected Version(s)

oidc-authorizer 0.1

oidc-authorizer 0.2

oidc-authorizer 0.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

changli (VulDB User)
VulDB CNA Team
.