pocket-id has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 4.3 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- github.com/pocket-id/pocket-id/backend 4
Worst active — by depth score
CVE-2026-43983HighPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions41GHSA-hp74-gm6m-2qm5MediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method28CVE-2026-55834Medium· 4.3Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services24GO-2026-6117NonePocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…3
pocket-id vulnerabilities
CVEs affecting pocket-id, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-55834Medium· 4.3Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…
GO-2026-6117NonePocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
CVE-2026-43983HighPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
GHSA-hp74-gm6m-2qm5MediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method