PatchSiren

doorkeeper-gem CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM doorkeeper-gem CVE published 2026-08-25

CVE-2026-70665

CVE-2026-70665 is a medium-severity vulnerability in Doorkeeper OpenID Connect, a gem that implements an OpenID Connect authentication provider for Rails applications. The issue allows a self-registered client to obtain scopes beyond what the server intended to grant due to a lack of validation on client-supplied scopes. This vulnerability is fixed in version 1.10.4.

MEDIUM doorkeeper-gem CVE published 2026-08-25

CVE-2026-44476

CVE-2026-44476 is a vulnerability in Doorkeeper, an OAuth 2 provider for Ruby on Rails. A dynamically registered client's client_id can be used to authenticate at the token endpoint without providing its client_secret, due to the confidential: false setting. This issue is fixed in version 1.10.0. The vulnerability allows an attacker who knows only a dynamically registered client's client_id, which is publ [truncated]