OIDC Provider Vulnerability in Pocket ID Affects User Authentication
CVE-2026-55834

4.3MEDIUM

Key Information:

Vendor

Pocket-id

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55834?

The Pocket ID OIDC provider, versions 2.6.0 through 2.9.0, contains a vulnerability that allows unauthenticated attackers to exploit the redirect_uri query parameter. This weakness arises when the platform fails to adequately validate the backend callback allow-list during the silent authorization process. Attackers can redirect authorized users to malicious HTTP or HTTPS sites, posing significant phishing threats and allowing for potential OIDC error and state smuggling attacks. This issue has been resolved in version 2.9.0.

Affected Version(s)

pocket-id >= 2.6.0, < 2.9.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.