{"id":"AZL-91682","summary":"CVE-2026-54431 affecting package liboauth 1.0.3-15","details":"In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.\n\nThis issue was fixed in version 2.3.0","modified":"2026-08-29T05:25:22Z","published":"2026-07-02T11:16:17Z","upstream":["CVE-2026-54431"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54431"}],"affected":[{"package":{"name":"liboauth","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/liboauth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.3-15"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91682.json"}}],"schema_version":"1.9.0"}