Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91679.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91679
Upstream
Published
2026-07-02T11:16:16Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-54430 affecting package liboauth 1.0.3-15
Details

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2josejwksawsalbresolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to albbase_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path.

This issue was fixed in version 2.3.0

References

Affected packages

Azure Linux:3 / liboauth

Package

Name
liboauth
Purl
pkg:rpm/azure-linux/liboauth

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.3-15

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91679.json"