Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91682.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91682
Upstream
Published
2026-07-02T11:16:17Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-54431 affecting package liboauth 1.0.3-15
Details

In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2tokenverify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.

This issue was fixed in version 2.3.0

References

Affected packages

Azure Linux:3 / liboauth

Package

Name
liboauth
Purl
pkg:rpm/azure-linux/liboauth

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.3-15

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91682.json"