GHSA-mp6j-4f9f-mcr2MediumCVSS 4.2

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

🔗 References (4)