Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91679.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91679
Upstream
Published
2026-07-02T11:16:16Z
Modified
2026-09-21T05:37:51Z
Summary
CVE-2026-54430 affecting package liboauth 1.0.3-15
Details

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path.

This issue was fixed in version 2.3.0

References

Affected packages

Azure Linux:3 / liboauth

Package

Name
liboauth
Purl
pkg:rpm/azure-linux/liboauth

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.3-15

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91679.json"