How to use this reference
Editorial reasoning: normalization must retain the strength and origin of evidence. A nonempty identity attribute is not interchangeable with proof of mailbox control. Review adapter contracts and the account-linking decision together; rejecting absent or unverified evidence must remain consistent across providers. Official auth@0.49.1 release notes dated 2026-04-17 corroborate stricter provider email-verification handling.
Before reading
- OAuth identity-provider claims and local account-linking concepts
Context and limits
- The advisory lists auth service versions before 0.49.1 as affected. Exposure depends on an affected provider adapter being enabled and an existing matching local identity. Provider-specific prerequisites differ; no universal OAuth-provider compromise is established.
- dbarrosop published the advisory; skoveit is credited as reporter. Technical claims are maintainer-reported, not independently reproduced.
- The advisory makes provider-specific assertions about Microsoft claims that were not independently corroborated; this record relies on the broader adapter-evidence boundary, not those assertions.
- Maintainer disclosure, not a peer-reviewed paper or an award-backed report. Software patch chronology is separate from resource edition metadata.
Sources and provenance
- Account Takeover via OAuth Email Verification Bypass Nhost · reviewed 2026-10-03
- Release auth@0.49.1 Nhost · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.