CWE-1391
CVEs classified under CWE-1391, newest first.
3 CVEsRSS
CVE-2026-46623High· 7.4Open Access Management (OpenAM) is an access management solution
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…
▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.49%via NVD
CVE-2026-45363Critical· 9.1ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', paylo…
▾ Midnightjwt · ruby-jwtEPSS 0.26%via NVD
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV