HIGH
erlef
CVE published 2026-08-30
CVE-2026-75759
The CVE-2026-75759 vulnerability is an Improper Verification of Cryptographic Signature issue in the erlef oidcc library. This vulnerability allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response that lacks a nested signature. The issue arises because the library incorrectly verifies cryptographic signatures, enabling anyone with the relying party's [truncated]