CVE-2026-19362
Received Received - Intake

Authorization Header Parsing DoS in oidc-authorizer

Vulnerability report for CVE-2026-19362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: VulDB

Description

A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lmammino oidc-authorizer 0.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the lmammino oidc-authorizer 0.4.0 software. It affects the function parse_token_from_header in the file src/parse_token_from_header.rs, specifically when handling the authorization_token argument. The issue allows an attacker to cause a denial of service by manipulating this token. The attack can be executed remotely and has been publicly disclosed.

Impact Analysis

If you use lmammino oidc-authorizer 0.4.0, an attacker could exploit this vulnerability to disrupt service availability by causing a denial of service. This could lead to system unavailability or degraded performance for legitimate users.

Compliance Impact

This vulnerability causes a denial of service due to improper handling of the authorization token in the oidc-authorizer component. It does not directly impact data confidentiality or integrity but may disrupt services, potentially affecting compliance with GDPR or HIPAA by causing service unavailability or delays in processing requests.

Mitigation Strategies

Update or patch the lmammino oidc-authorizer to a version that fixes the denial of service vulnerability in the authorization header parsing function. If no patch is available, consider disabling the affected component or implementing network-level protections to block malformed authorization headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart