Junglewise Threat Intelligence

CVE-2026-54431: OpenIDC liboauth2 improper security check in DPoP verifier

CVE-2026-54431 · Severity: info · CVSS 5.1 · Published 2026-07-02

Vendors: Openidc.

Executive brief

OpenIDC liboauth2 is a library used to handle OAuth 2.0 and OpenID Connect authentication. A vulnerability in its DPoP (Demonstrating Proof-of-Possession) verification component allows malformed security proofs to be accepted even when they contain sensitive private key material. This could potentially lead to the exposure of cryptographic keys or the bypass of certain security checks intended to verify the sender's identity.

Technical details

A vulnerability exists in liboauth2's DPoP verifier where the oauth2_token_verify() function fails to reject proofs containing private key material in the JWK header. This violates RFC 9449 section 4.3 step 7, which mandates that verifiers must reject such proofs. The root cause is located in the _oauth2_dpop_parse_and_validate() function within src/dpop.c, which returns success for malformed proofs embedding private Elliptic Curve (EC) keys. An attacker could potentially exploit this improper security check (CWE-358) to submit invalid proofs that should be discarded. The issue is resolved in version 2.3.0.

Affected products

  • OpenIDC liboauth2 < 2.3.0

Timeline

  • 2026-06-02: patched: Fix committed to repository
  • 2026-07-02: disclosed: CVE published by CERT.PL

References

Related threats