[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-82454":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-30T02:56:26.384Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":28,"duplicate_of":9,"upstream":29,"downstream":30,"duplicates":31,"related":32,"reserved_at":9,"published_at":33,"modified_at":33,"state":34,"summary":35,"references_raw":42,"kevs":64,"epss":9,"epss_history":65,"metrics":66,"affected":79},"CVE-2026-82454","The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 and sign a forged token using Apple's publicly available RSA public key as the HMAC secret, bypassing signature verification and impersonating any Apple-linked account.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-347","Improper Verification of Cryptographic Signature","The product does not verify, or incorrectly verifies, the cryptographic signature for data.","weakness","Draft","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-463","Padding Oracle Crypto Attack",[],{"id":24,"name":25,"techniques":26},"CAPEC-475","Signature Spoofing by Improper Validation",[],[],[],[],[],[],[],"2026-08-29T13:47:56.108Z","Received",{"cisa_kev":36,"cisa_ransomware":36,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":37,"severity_score":38,"severity_version":39,"severity_source":40,"severity_vector":41,"severity_status":34},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",[43,50,54,59],{"url":44,"sources":45,"tags":47},"https://github.com/omnivore-app/omnivore/pull/4652",[40,46],"nvd",[48,49],"Issue Tracking","Patch",{"url":51,"sources":52,"tags":53},"https://github.com/omnivore-app/omnivore/commit/abf53d6508755d3d22a994e28e370a9193ea977a",[40,46],[49],{"url":55,"sources":56,"tags":57},"https://github.com/omnivore-app/omnivore",[40,46],[58],"Product",{"url":60,"sources":61,"tags":62},"https://www.vulncheck.com/advisories/omnivore-before-android-0.227.0-authentication-bypass-via-apple-sign-in",[40,46],[63],"Third Party Advisory",[],[],[67,75],{"source":40,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":68,"cvss_v4_0":74},{"baseScore":69,"baseSeverity":70,"vectorString":71,"impactScore":72,"exploitabilityScore":73},9.1,"CRITICAL","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",8.7,10,{"baseScore":38,"baseSeverity":70,"vectorString":41,"impactScore":9,"exploitabilityScore":9},{"source":46,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":76,"cvss_v4_0":77},{"baseScore":69,"baseSeverity":70,"vectorString":71,"impactScore":72,"exploitabilityScore":73},{"baseScore":38,"baseSeverity":70,"vectorString":78,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[80],{"ecosystem":9,"name":81,"vendor":82,"product":81,"cpe_part":83,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":84},"omnivore","omnivore-app","a",[85],{"version":86,"is_range":87,"range_type":40,"version_start":9,"version_start_type":9,"version_end":88,"version_end_type":89,"fixed_in":9},"\u003C abf53d650875",true,"abf53d650875","excluding"]