All 2 CVE vulnerabilities found in oidcc_plug, with AI-generated Chinese analysis, references, and POCs.
Vendor: Erlang Ecosystem Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-66883 | Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup CWE-178 | 6.3 | Medium | 2026-08-04 |
| CVE-2026-66884 | Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection CWE-352 | 2.1 | Low | 2026-08-04 |
All 2 known CVE vulnerabilities affecting oidcc_plug with full Chinese analysis, references, and POCs where available.