What is CVE-2026-19363?
This vulnerability affects lmammino oidc-authorizer up to version 0.4.0. The Lambda Authorizer component in `src/handler.rs` logs the raw Authorization header, leading to sensitive information exposure in log files. It is remotely exploitable; review your logging configuration.
Azərbaycanca: Bu boşluq lmammino oidc-authorizer alətinin 0.4.0 versiyasına qədər təsir edir. `src/handler.rs` faylındakı Lambda Authorizer komponenti Authorization başlığını log fayllarına çiy şəkildə yazaraq həssas məlumatların sızmasına səbəb olur. Uzaqdan istismar mümkündür, log konfiqurasiyasını yoxlayın.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions does CVE-2026-19363 affect in oidc-authorizer?
This vulnerability affects lmammino oidc-authorizer up to version 0.4.0.
Which component is responsible for the log leakage in CVE-2026-19363?
The Lambda Authorizer component in `src/handler.rs` logs the raw Authorization header into log files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.