build1 distinct publisher
authentik checked the PKCE verifier only when the request bothered to include one
One authentik CVE covers a token endpoint accepting a missing code_verifier; another, six months later, covers an authorization endpoint accepting a missing code_challenge. OpenAM's equivalent check ships switched off.
Publishers:dev.to
Reality
- Evidence60
- Adoption45
- Hype gap+15
- Incentives20