A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. This vulnerability only affects products that are no longer supported by the maintainer.
[POC] CVE-2026-43499 — CVE-2026-43499-popsicle
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
[POC] CVE-2026-43499 — CVE-2026-43499-Neo11Plus
the CVE-2026-43499 by iqooneo11
[POC] CVE-2026-43499 — GhostLock-Galaxy
Root your Galaxy using CVE-2026-43499
[POC] CVE-2026-43499 — Mi8E5-Unlocker-by-CVE-2026-43499
基于 CVE-2026-43499 的 8E5 机型自动化解锁辅助工具,仅限授权安全研究与自有设备使用。
[POC] CVE-2026-43499 — tcp-zerocopy-sm
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 port
[POC] CVE-2026-43499 — root-my-s9280
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
[POC] CVE-2026-43499 — ghostlock-oneplus
GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader
[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-43499-S25U
Galaxy S25 Ultra SM-S938N S938NKSUACZF1 port of CVE-2026-43499
[POC] CVE-2026-43499 — GhostLock-5.10
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
[POC] CVE-2026-43499 — ghostlock-cve-2026-43499-4.19-k40
CVE-2026-43499 (GhostLock) rtmutex remove_waiter() UAF local-root PoC adapted for Qualcomm Android 4.19 kernels (Redmi K40 / Snapdragon 870 class), LD_PRELOAD based
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free