The Omniauth Apple Project maintains a focused Ruby authentication library that integrates Apple's sign-in provider into web applications, serving a narrow but critical role in the third-party authentication supply chain. The library's limited vulnerability surface reflects its specialized scope as a single authentication middleware component. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omniauth Apple Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26254HIGH omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during auth | Dec 8, 2020 | 7.7 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omniauth Apple Project.
Media articles that mention a CVE ID that affects a product developed by Omniauth Apple Project — matched by CVE ID, not by vendor name.