CVE-2026-19363

Summary

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. src/handler.rs logs raw Authorization header values and complete bearer tokens/JWTs on authentication failure paths, potentially exposing credentials through CloudWatch Logs. src/models.rs serializes the complete validated JWT claims set with serde_json::to_string(token_claims).unwrap() and propagates it through context["jwtClaims"] to downstream integrations. This code performs serialization, not deserialization, and does not process attacker-controlled jwtClaims input. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
lmamminooidc-authorizer0.1affected
lmamminooidc-authorizer0.2affected
lmamminooidc-authorizer0.3affected
lmamminooidc-authorizer0.4.0affected

Weaknesses

  • CWE-532: Sensitive Information in Log Files
  • CWE-200: Information Disclosure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References