๐Ÿ” CVE Alert

CVE-2026-44476

UNKNOWN 0.0

Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secret

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.

CWE CWE-287 CWE-1390
Vendor doorkeeper-gem
Product doorkeeper-openid_connect
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for doorkeeper-gem doorkeeper-openid_connect

Be the first to know when new unknown vulnerabilities affecting doorkeeper-gem doorkeeper-openid_connect are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

doorkeeper-gem / doorkeeper-openid_connect
>= 1.9.0, < 1.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h github.com: https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf