CVE-2026-82454 | omnivore-app Omnivore Apple Sign-In Token Verification packages/api decodeAppleToken alg signature verification (abf53d650875)
A vulnerability was found in omnivore-app Omnivore. It has been declared as critical. The affected element is the function decodeAppleToken of the file packages/api of the component Apple Sign-In Token Verification. Executing a manipulation of the argument alg can lead to improper verification of cryptographic signature.
This vulnerability appears as CVE-2026-82454. The attack may be performed from remote. There is no available exploit.
A patch should be applied to remediate this issue.VulDB Recent EntriesRead More