Skip to content
CloudflareGHSA-qgp8-v765-qxx9

PKCE bypass via downgrade attack

Medium5.3CVE-2025-4144 · Published May 1, 2025

### Summary PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of[ MCP framework](https://github.com/cloudflare/workers-mcp). However, it was found that an attacker could cause the check to be skipped. ### Impact PKCE is a defense-in-depth mechanism against certain kinds of attacks and was an optional extension in OAuth 2.0 which became required in the OAuth 2.1 draft. (Note that the MCP specification requires OAuth 2.1.) This bug completely bypasses PKCE protection. ### Patches Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/27 We patched up the vulnerabilities in the latest version, v 0.0.5 of the Workers OAuth provider (https://www.npmjs.com/package/@cloudflare/workers-oauth-provider). You'll need to update your MCP servers to use that version to resolve the vulnerability. ### Workarounds None

GitHub advisory

Affected versions

PackageAffectedFixed in
workers-oauth-provider
Product
< 0.0.50.0.5
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287

More Cloudflare advisories

All Cloudflare
Advisory
Cloudflare vite plugin exposes secrets over the built-in dev server
LowJul 7, 2025
Request Smuggling Vulnerability in Pingora
High7.4Jun 20, 2025
Incorrect congestion window growth by invalid ACK ranges
High7.5Jun 17, 2025
Incorrect congestion window growth by optimistic ACK
Medium5.3Jun 17, 2025
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
LowJun 10, 2025
Missing validation of redirect_uri on authorize endpoint
Medium6.0May 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.