Browse all 5 CVE security advisories affecting ueberauth. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55734 | guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1 — guardian CWE-770 | 6.9 | Medium | 2026-08-01 |
| CVE-2026-55733 | Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation — guardian CWE-770 | 6.9 | Medium | 2026-08-01 |
| CVE-2026-54894 | Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys — guardian CWE-770 | 6.9 | Medium | 2026-08-01 |
| CVE-2026-55735 | Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation — guardian CWE-347 | 8.2 | High | 2026-08-01 |
| CVE-2026-55954 | Missing ID token claim validation in ueberauth_apple allows account takeover — ueberauth_apple CWE-290 | - | - | 2026-07-14 |
This page lists every published CVE security advisory associated with ueberauth. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.