boruta
Hex3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting borutapage 1 of 1
- CVE-2026-53431CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.3.72026-07-30
vulnerable: 2.3.0 ... 2.3.6 (7 versions)
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta acce…
- CVE-2026-54885MEDIUMCVSS 6.9EG 6.9✓ Fixed in 2.3.72026-07-30
vulnerable: 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6
Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and…
- CVE-2026-65635HIGHCVSS 8.3EG 8.3✓ Fixed in 2.3.72026-07-30
vulnerable: 2.3.0 ... 2.3.6 (7 versions)
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry poi…
Check whether boruta is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for boruta CVEs against the assets you own.
Start Free Scan →