OIDC Provider Vulnerability in Pocket ID Affects User Authentication
CVE-2026-55834
4.3MEDIUM
What is CVE-2026-55834?
The Pocket ID OIDC provider, versions 2.6.0 through 2.9.0, contains a vulnerability that allows unauthenticated attackers to exploit the redirect_uri query parameter. This weakness arises when the platform fails to adequately validate the backend callback allow-list during the silent authorization process. Attackers can redirect authorized users to malicious HTTP or HTTPS sites, posing significant phishing threats and allowing for potential OIDC error and state smuggling attacks. This issue has been resolved in version 2.9.0.
Affected Version(s)
pocket-id >= 2.6.0, < 2.9.0
