Impact
The vulnerability resides in the parse_token_from_header function of lmammino oidc-authorizer 0.4.0, where an attacker can supply a crafted Authorization header that causes the service to crash, resulting in denial of service. The flaw is a resource‑exhaustion weakness described by CWE-404.
Affected Systems
Affected systems are installations of lmammino oidc-authorizer version 0.4.0. No other versions or vendors are known to be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Remote exploitation is possible and the exploit has been publicly disclosed, but the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. The lack of vendor response elevates the risk until a patch is applied, and attackers could trigger service outages from outside the network.
OpenCVE Enrichment