Junglewise Threat Intelligence

CVE-2026-41213: node-oauth oauth2-server brute-force vulnerability in PKCE token exchange

CVE-2026-41213 · Severity: medium · CVSS 5.9 · Published 2026-04-23

Vendors: npm.

Executive brief

A vulnerability in the node-oauth2-server library allows attackers to bypass security protections designed to prevent the theft of login tokens. The software fails to properly validate security codes and does not deactivate them after failed attempts, allowing an attacker who has intercepted a temporary authorization code to guess the secret key through repeated attempts. If successful, an attacker can gain unauthorized access to user accounts and sensitive data.

Technical details

The vulnerability exists in the token exchange path of @node-oauth/oauth2-server where it handles Proof Key for Code Exchange (PKCE) flows. Specifically, 'lib/pkce/pkce.js' only checks if a verifier is a non-empty string rather than enforcing the RFC7636 ABNF requirement of 43-128 unreserved characters. Furthermore, 'lib/grant-types/authorization-code-grant-type.js' performs authorization code revocation only after verifier validation; because invalid guesses fail before revocation occurs, an attacker who has intercepted an authorization code can perform an online brute-force attack against the code_verifier. This is particularly effective if the client generated a weak or short verifier. The issue is patched in version 5.3.0.

Affected products

  • node-oauth oauth2-server <= 5.2.1

Timeline

  • 2026-04-15: advisory: GitHub Security Advisory published
  • 2026-04-23: disclosed: CVE published to NVD
  • 2026-06-02: patched: NIST analysis completed and patch version 5.3.0 confirmed

References