VulnSea

pocket-id has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 4.3 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.3
Publish → KEV
Last 90 days
4 prev 0

Products

  • github.com/pocket-id/pocket-id/backend 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pocket-id vulnerabilities

CVEs affecting pocket-id, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-55834Medium· 4.3
3w ago

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…

Sunlitpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.27%via NVD
GO-2026-6117None
1mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia OSV
CVE-2026-43983High
1mo ago

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Twilightpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.25%via GHSA
GHSA-hp74-gm6m-2qm5Medium
1mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia GHSA
pocket-id vulnerabilities (CVEs) · VulnSea