CVE Tools

Openidc

6 CVEs tracked since 2017. Since Mar 2017, none of them reached CISA KEV.

Openidc CVEs per month

Mar 2017 to Jul 2021. Point at a month, or focus the strip and use the arrow keys.
Openidc CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0320
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-0740

Products

The products that kept showing up in Openidc's monthly top three, with their CVEs summed over those months.

  1. Mod Auth Openidc62 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Openidc.

  1. CVE-2026-53939OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption9.1
  2. CVE-2026-53938OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)8.2
  3. CVE-2026-54789mod_auth_openidc has out-of-bounds read and write in state cookie parsing7.5
  4. CVE-2026-54431Improper Data Validation in liboauth2—
  5. CVE-2026-54430Server-Site Request Forgery in liboauth2—
  6. CVE-2025-31492mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data7.5
  7. CVE-2024-24814Denial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidc7.5
  8. CVE-2023-37464Incorrect Authentication Tag length usage in AES GCM decryption in OpenIDC/cjose8.6
  9. CVE-2023-28625mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied7.5
  10. CVE-2022-23527Open Redirect in oidc_validate_redirect_url()4.7
  11. CVE-2021-39191URL Redirection to Untrusted Site ('Open Redirect') in mod_auth_openidc4.7
  12. CVE-2021-32791Hardcoded static IV and AAD with a reused key in AES GCM encryption in mod_auth_openidc5.9
  13. CVE-2021-32792XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc3.1
  14. CVE-2021-32785Format string bug in the Redis cache implementation5.3
  15. CVE-2021-32786Open Redirect in oidc_validate_redirect_url()4.7

The record

Peak rank
#113 in Jul 2021
Busiest month shown
Jul 2021, 4 CVEs
Months with a KEV entry
0 since Mar 2017
Monthly snapshots
2 since 2017
Openidc's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store