Pocket-id

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-55834

    Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

    Last Modified: Aug 28, 2026
    Published: Aug 28, 2026

    CVE-2026-43983

    Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2026-28513

    Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange

    Last Modified: Apr 17, 2026
    Published: Mar 09, 2026

    CVE-2026-28512

    Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion

    Last Modified: Apr 17, 2026
    Published: Mar 09, 2026
    Items Per Page