All 3 CVE vulnerabilities found in medplum, with AI-generated Chinese analysis, references, and POCs.
Vendor: medplum
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44506 | Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations CWE-200 | 8.2 | High | 2026-09-03 |
| CVE-2026-53728 | Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage CWE-601 | 7.1 | High | 2026-09-03 |
| CVE-2026-49120 | Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint CWE-918 | 8.5 | High | 2026-06-02 |
All 3 known CVE vulnerabilities affecting medplum with full Chinese analysis, references, and POCs where available.