Security: node-oauth/node-oauth2-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codesGHSA-jhm7-29pj-4xvf published
Apr 15, 2026 by jankapunktModerate