All 3 CVE vulnerabilities found in boruta, with AI-generated Chinese analysis, references, and POCs.
Vendor: malach-it
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53431 | Boruta accepts expired JWT client assertions due to missing exp claim validation CWE-294 | 9.1 | Critical | 2026-07-30 |
| CVE-2026-65635 | Boruta dynamic client registration allows creation of over-privileged OAuth clients CWE-653 | 8.3 | High | 2026-07-30 |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching CWE-918 | 6.9 | Medium | 2026-07-30 |
All 3 known CVE vulnerabilities affecting boruta with full Chinese analysis, references, and POCs where available.