Pocket Id maintains a focused digital identity and authentication platform that serves a specialized market within credential and identity management. The vendor's narrow product footprint and observed weakness classes are shown alongside current exposure counts in the live statistics panel.
The number and severity of CVEs published that impact products developed by Pocket Id over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43983HIGH Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) val | May 12, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-28513HIGH Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only whe | Mar 10, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-28512MEDIUM Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted | Mar 10, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pocket Id.
Media articles that mention a CVE ID that affects a product developed by Pocket Id — matched by CVE ID, not by vendor name.