Yopass: unverified emails could pass OIDC domain restrictions
Yopass is an open-source tool (over 3,000 GitHub stars) for securely sharing secrets, passwords and files. When it is set to allow logins only from certain email domains, its OIDC login trusted the email address returned by the identity provider without checking the email_verified claim. Someone with an unverified account at an identity provider under an allowed domain could therefore get past the domain restriction.
- 23 Sep 2026. BudgetScan flagged the missing check. We opened a pull request with a fix and tests.
- 24 Sep. An automated review asked for stronger tests, which we added. The maintainer pointed out that
email_verifiedis an optional claim, so enforcing it blindly could break existing setups. - 25 Sep. Maintainer Johan Haals built on our patch in a new pull request: he kept our commit as the first one, with its authorship, and added an explicit opt-out for providers that omit the claim, a startup warning, configuration validation, tests and documentation.
- 26 Sep. Merged into Yopass. By default, OIDC logins now require a verified email.
- Read the full story →
- Our original pull request (#3966)
- The merged pull request (#3973)
- Our patch as its first commit
How to read this. Thanks to Johan Haals for the quick, careful handling. The scanner found the problem and a human maintainer decided how to fix it safely, which is how we want it to work: findings are leads for people, not verdicts. It is one data point, not a benchmark. We will publish measured results once we have them.