PatchSiren

erlef CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH erlef CVE published 2026-08-30

CVE-2026-75759

The CVE-2026-75759 vulnerability is an Improper Verification of Cryptographic Signature issue in the erlef oidcc library. This vulnerability allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response that lacks a nested signature. The issue arises because the library incorrectly verifies cryptographic signatures, enabling anyone with the relying party's [truncated]