Debian Package Tracker
Register | Log in
Subscribe

liboauth2

Choose email to subscribe with

general
  • source: liboauth2 (main)
  • version: 2.3.0-1
  • maintainer: Debian IoT Maintainers (archive) (DMD)
  • uploaders: Nicolas Mora [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.0.1-1
  • oldstable: 1.4.5.4-1
  • stable: 2.1.0-2
  • testing: 2.3.0-1
  • unstable: 2.3.0-1
versioned links
  • 1.4.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.5.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • liboauth2-1
  • liboauth2-apache-dev
  • liboauth2-apache1
  • liboauth2-dev
action needed
2 security issues in bullseye high

There are 2 open security issues in bullseye.

2 important issues:
  • CVE-2026-54430: liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0
  • CVE-2026-54431: In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header. This issue was fixed in version 2.3.0
Created: 2026-07-02 Last update: 2026-07-09 18:20
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2026-54430: liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0
  • CVE-2026-54431: In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header. This issue was fixed in version 2.3.0
Created: 2026-07-02 Last update: 2026-07-09 18:20
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-54430: (needs triaging) liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0
  • CVE-2026-54431: (needs triaging) In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header. This issue was fixed in version 2.3.0

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-02 Last update: 2026-07-09 18:20
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-06-27] liboauth2 2.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-24] Accepted liboauth2 2.3.0-1 (source) into unstable (Nicolas Mora)
  • [2026-04-12] liboauth2 2.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-09] Accepted liboauth2 2.2.1-1 (source) into unstable (Nicolas Mora)
  • [2026-02-24] liboauth2 2.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-21] Accepted liboauth2 2.2.0-2 (source amd64) into unstable (Debian FTP Masters) (signed by: Nicolas Mora)
  • [2026-01-11] liboauth2 2.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-09] Accepted liboauth2 2.2.0-1 (source) into unstable (Nicolas Mora)
  • [2025-08-25] liboauth2 2.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-23] Accepted liboauth2 2.1.1-1 (source) into unstable (Nicolas Mora)
  • [2025-04-03] liboauth2 2.1.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-30] Accepted liboauth2 2.1.0-2 (source) into unstable (Nicolas Mora)
  • [2025-02-15] liboauth2 2.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-13] Accepted liboauth2 2.1.0-1 (source) into unstable (Nicolas Mora)
  • [2024-08-30] liboauth2 2.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-28] Accepted liboauth2 2.0.0-1 (source) into unstable (Nicolas Mora)
  • [2024-06-30] liboauth2 1.6.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-28] Accepted liboauth2 1.6.3-1 (source) into unstable (Nicolas Mora)
  • [2024-06-17] liboauth2 1.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-13] Accepted liboauth2 1.6.2-1 (source) into unstable (Nicolas Mora)
  • [2024-05-03] liboauth2 1.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-29] Accepted liboauth2 1.6.1-1 (source) into unstable (Nicolas Mora)
  • [2023-12-10] liboauth2 1.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-07] Accepted liboauth2 1.6.0-1 (source) into unstable (Nicolas Mora)
  • [2023-11-16] liboauth2 1.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-14] Accepted liboauth2 1.5.2-1 (source) into unstable (Nicolas Mora)
  • [2023-07-04] liboauth2 1.5.1-3 MIGRATED to testing (Debian testing watch)
  • [2023-07-01] Accepted liboauth2 1.5.1-3 (source) into unstable (Nicolas Mora)
  • [2023-06-27] Accepted liboauth2 1.5.1-2 (source) into experimental (Nicolas Mora)
  • [2023-06-25] Accepted liboauth2 1.5.1-1 (source) into unstable (Nicolas Mora)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.2.0-2ubuntu1
  • patches for 2.2.0-2ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing