News · via oss-security
CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
Posted by Timothy Legge on Sep 24 ======================================================================== CVE-2026-92289 CPAN Security Group…
