What is CVE-2026-19362?
The lmammino oidc-authorizer 0.4.0 contains a denial-of-service vulnerability in the `parse_token_from_header` function due to improper handling of the Authorization header. Remote exploitation is possible. Affected deployments should apply patches as soon as available.
Azərbaycanca: lmammino oidc-authorizer 0.4.0 versiyasında `Authorization` başlığındakı token-in emalı zamanı `parse_token_from_header` funksiyasında aşkar edilmiş zəiflik uzaqdan xidmət dayandırmaya (DoS) səbəb olur. İstismar üçün şəbəkə girişi kifayətdir. Təsirə məruz qalan sistemlərin mümkün qədər tez yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which version of lmammino oidc-authorizer is affected by CVE-2026-19362?
This vulnerability affects version 0.4.0 of lmammino oidc-authorizer.
What does an attacker need to exploit CVE-2026-19362?
Network access is sufficient for exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.