GHSA-gqx7-6552-67hf
HIGHCVE-2026-45575An attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects u ripukidpenc and uripukidpsig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed au
- Affected
- < 1.2.2
- Fixed in
- 1.2.2
- Weakness
- CWE-347
- Published
- 2026-05-15
- Source
- github