Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Squeeze440

#34347of 57,416
8.1Total CVSS
Vulnerabilities · 1
PT-2026-103472
8.1
2026-09-30
Tugtainer · Tugtainer · CVE-2026-87004
**Name of the Vulnerable Software and Affected Versions** Tugtainer versions prior to 1.31.3 **Description** During the OIDC login flow, the file `backend/modules/auth/providers/auth oidc provider.py` decodes the `id token` returned by the identity provider using `jose.jwt.get unverified claims()` instead of `jwt.decode()`. This process bypasses signature verification, audience (`aud`) validation, issuer (`iss`) validation, and expiry (`exp`) checking. Consequently, the extracted claims such as `email`, `sub`, or `preferred username` are used directly as the `user id` for the session. **Recommendations** Update to version 1.31.3.