https://seclists.org/oss-sec/2026/q3/505: CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 befo2.16.9, from 2.17.0 befo2.21.5, from 2.22.0 befo2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stod as an SSO session in the GitHub and LinkedIn backends
Published Aug 16, 2026
·Updated
Affected Software
1 affected component
lemonldap-ng Lemonldap::NG::Portal>2.0.0<=2.16.9, >2.17.0<=2.21.5, >2.22.0<=2.23.3
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using the GitHub or LinkedIn OAuth2 backends in Lemonldap::NG::Portal are affected when running an affected version.
2
Which versions contain the fix?
The fixed versions are 2.16.9, 2.21.5, and 2.23.3 for their respective release branches. Upgrade to the applicable fixed version or a later release in that branch.