CVE-2026-92289

NameCVE-2026-92289
DescriptionLemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when the request carries no code_challenge, and token() admits the exchange as long as a challenge was stored or an authentication method was returned for the caller. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the method deduced from the request, so any Basic or form credential satisfies the secret branch. validatePKCEChallenge() then passes, because neither a challenge nor a verifier is present. An attacker who intercepts an authorization code issued to a public Relying Party can exchange it for the user's access, ID and refresh tokens by replaying the client_id with an arbitrary secret, which is the attack PKCE prevents. Dynamic client registration creates every Relying Party in this mode.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6520-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)bookworm2.16.1+ds-deb12u8fixed
bookworm (security)2.16.1+ds-deb12u10fixed
trixie2.21.2+ds-1+deb13u3vulnerable
trixie (security)2.21.2+ds-1+deb13u4fixed
sid2.23.4+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcebookworm(not affected)
lemonldap-ngsourcetrixie2.21.2+ds-1+deb13u4DSA-6520-1
lemonldap-ngsource(unstable)2.23.4+ds-1

Notes

[bookworm] - lemonldap-ng <not-affected> (Vulnerable code introduced later)
https://lists.security.metacpan.org/cve-announce/msg/43830168/
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719

Search for package or bug name: Reporting problems