Hsiaoming Yang
12 exploits
Active since Dec 2017
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVSS 7.5
Authlib JWS JWK Header Injection: Signature Verification Bypass
CVSS 9.1
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
Authlib 1.6.5-1.6.6 - Auth Bypass
CVSS 9.8
joserfc <=1.6.2 - DoS
CVSS 7.5
Mistune <0.8.1 - XSS
CVSS 6.1
Mistune <2.0.2 - Code Injection
CVSS 7.5
Authlib < 1.6.4 - Incorrect Authorization
CVSS 7.5
Authlib < 1.6.5 - Denial of Service
CVSS 7.5
Authlib < 1.6.5 - Denial of Service
CVSS 6.5
Hsiaoming Joserfc < 1.3.5 - Resource Allocation Without Limits
CVSS 7.5
Authlib < 1.6.6 - CSRF
CVSS 5.7