github.com/pocket-id/pocket-id/backend vulnerabilities
CVEs whose affected-version data names the github.com/pocket-id/pocket-id/backend package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-55834Medium· 4.3Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…
GO-2026-6117NonePocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
CVE-2026-43983HighPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
GHSA-hp74-gm6m-2qm5MediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method