Callback URL Validation Bypass in Pocket ID OIDC Provider
CVE-2026-28512
7.1HIGH
What is CVE-2026-28512?
A security flaw in the Pocket ID OIDC provider, present in versions 2.0.0 to prior to 2.4.0, allows attackers to bypass legitimate callback URL validation. By manipulating redirect_uri parameters, an attacker can redirect authorization codes to an unauthorized host. This can occur if a user unwittingly accesses a malicious authorization link. It is crucial for users of Pocket ID to upgrade to version 2.4.0 or later to mitigate this vulnerability.
Affected Version(s)
pocket-id >= 2.0.0, < 2.4.0
