Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

github логотип

GHSA-223h-642r-2f6v

около 2 месяцев назад

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2026-16615

около 2 месяцев назад

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2026-16615

3 месяца назад

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-16615

около 2 месяцев назад

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2026-16615

около 2 месяцев назад

Librest: weak random number generation in pkce implementation

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2026-16615

около 2 месяцев назад

A flaw was found in librest. The PKCE implementation for OAuth authori ...

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21694-1

16 дней назад

Security update for librest

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21563-1

около 1 месяца назад

Security update for librest0_7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3834-1

19 дней назад

Security update for librest0_7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3796-1

21 день назад

Security update for librest

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3795-1

21 день назад

Security update for librest

EPSS: Низкий
rocky логотип

RLSA-2026:47085

около 2 месяцев назад

Important: rest security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47085

около 2 месяцев назад

ELSA-2026-47085: rest security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-223h-642r-2f6v

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-16615

Librest: weak random number generation in pkce implementation

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authori ...

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21694-1

Security update for librest

0%
Низкий
16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21563-1

Security update for librest0_7

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3834-1

Security update for librest0_7

0%
Низкий
19 дней назад
suse-cvrf логотип
SUSE-SU-2026:3796-1

Security update for librest

0%
Низкий
21 день назад
suse-cvrf логотип
SUSE-SU-2026:3795-1

Security update for librest

0%
Низкий
21 день назад
rocky логотип
RLSA-2026:47085

Important: rest security update

0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-47085

ELSA-2026-47085: rest security update (IMPORTANT)

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу