PatchSiren

Lemonldap::NG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Lemonldap::NG CVE published 2026-08-16

CVE-2026-19349

The Lemonldap::NG::Portal, specifically versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, and from 2.22.0 before 2.23.3, is vulnerable to an authentication bypass attack via an OAuth2 state parameter stored as an SSO session in GitHub and LinkedIn backends. This vulnerability arises from the mishandling of the state session in the extractFormInfo() function, allowing any visitor to replay the [truncated]