Merged 26 Sep 2026  First hit on open source

Yopass: unverified emails could pass OIDC domain restrictions

BudgetScan flagged a missing email_verified check in the login of Yopass, an open-source tool for sharing secrets, passwords and files. Our patch became the first commit of the maintainer's merged fix.

What was wrong

In an OIDC login, the identity provider returns claims about the user: the email address and, optionally, email_verified, which says whether the provider actually checked that address. Yopass used the email to enforce its list of allowed email domains (the AllowedEmailDomains setting) but did not look at email_verified. OIDC is an optional, licensed feature of Yopass; when it is configured, a Sign in button appears in the navbar.

So someone with an unverified account at an identity provider under an allowed domain could get past the domain restriction. Whether that is possible in practice depends on the identity provider.

Simplified OIDC login flow in Yopass The identity provider returns the email and optionally email_verified. Before the fix the email went straight to the allowed-domain check. Now a verified-email check sits in between. Identity providerreturns email and, optionally, email_verified Yopass login callbackreads the UserInfo claims NEW: email_verified must be truemissing or false: login rejected Allowed email domains checkAllowedEmailDomains Session createdthe user is signed in beforethe fix
A simplified sketch of the login flow, not a screenshot. Before the fix, the email went straight from the callback to the domain check (dashed line).
Illustration of Yopass: a Sign in link in the navbar when OIDC is enabled, and, before the fix, a user whose email the provider reported as unverified being signed in anyway.
Illustration of the finding (not a screenshot). (1) With OIDC configured, a Sign in link appears in the navbar. (2) Before the fix, a login whose email the provider had not verified was still accepted.

How it was fixed

Our first patch rejected logins whose email was not verified, logged the attempt, and added tests. The maintainer, Johan Haals, pointed out that email_verified is an optional claim, so enforcing it blindly could break existing setups. He built on our commit in a new pull request, which:

Our original commit was kept as the first commit of that pull request, with its authorship.

Timeline

How to read this

The scanner found the problem and a human maintainer decided how to fix it safely. That is how we want it to work: findings are leads for people, not verdicts. It is one data point, not a benchmark, and we will publish measured results once we have them. Thanks to Johan Haals for the quick, careful handling.

Sources

← Back to Success Stories