CVE Feed

    Dashboard / CVE / CVE-2026-41213

    CVE-2026-41213

    @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code, an attacker who intercepts an authorization code can brute-force code_verifier guesses online until token issuance succeeds.

    Published:Apr 23, 2026
    Last Modified:Jun 2, 2026
    EPS:Apr 23, 2026
    EPSS Score:0.0006
    CVSS Score:5.9

    Affected Products

    Vendor
    Node-oauth
    Product
    Node-oauth2-server
    Vendor
    Node-oauth
    Product
    Node-oauth\/oauth2-server

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High