HIGHGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

CVE-2026-43983Published 4 weeks agoUpdated 1 week agoSource: OSV

Affected packages

  • github.com/pocket-id/pocket-id/backend

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions | HackTribune