QSearchQSearch

CVE-2026-41213

5.9 MEDIUM

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js

Published: 2026-04-23 · Last updated: 2026-06-02

Severity and scoring

CVSS
5.9 MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-1289, CWE-307

Affected products

VendorProduct
node-oauthnode-oauth\/oauth2-server

Description

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code, an attacker who intercepts an authorization code can brute-force code_verifier guesses online until token issuance succeeds.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-42462 Fedify is a TypeScript library for building federated server apps powered by ActivityPub (7.0 HIGH)
  • CVE-2026-49942 Net::CIDR::Set versions through 0.20 for Perl did not validate network masks (7.3 HIGH)
  • CVE-2026-49940 Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks (6.5 MEDIUM)
  • CVE-2026-43926 FOSSBilling is a free, open-source billing and client management system
  • CVE-2026-36612 Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 1... (6.4 MEDIUM)