HIGH GitHub

CVE-2026-43983

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

# OIDC Refresh Token Flow Bypasses Authorization Revocation, Account Disabling, and Group Restrictions ## Summary The `createTokenFromRefreshToken` function (oidc_service.go:451) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. This allows three bypasses: 1. **Authorization revocation bypass**: After a user revokes an OIDC client's authorization, the client can continue refreshing tokens indefinite

Affected Products

References

Published: 2026-07-28 · Source: GitHub · Feed updated: 2026-08-04
This high severity vulnerability was published on 2026-07-28 via GitHub. Affected: go/github.com/pocket-id/pocket-id/backend < 0.0.0-20260419162744-978ac87deffe.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.