CVE-2026-28513 Details
Description
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. This vulnerability is fixed in 2.4.0.
A vulnerability exists in Pocket ID OIDC provider versions through 2.3.0, allowing improper validation of authorization codes at the OIDC token endpoint. The endpoint only rejects an authorization code when both the client ID is incorrect and the code is expired. This flaw enables cross-client code exchange and the reuse of expired authorization codes. The issue is resolved in version 2.4.0.
Users should update to Pocket ID version 2.4.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pocket-id/pocket-id/security/advisories/GHSA-qh6q-598w-w6m2 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/pocket-id/pocket-id/security/advisories/GHSA-qh6q-598w-w6m2 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pocket-id pocket id | < 2.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Mar 10, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | New CVE Received | [email protected] |