—Hex
EEF-CVE-2026-66883· CVE-2026-66883, GHSA-w5r8-m75h-98fcOidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Modified: 9/8/2026
package
pkg:hex/oidcc_plug
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Modified: 9/8/2026
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Modified: 9/8/2026