Feed/CVE-2026-56664
CVE-2026-56664MEDIUMCVSS 4.2

CVE-2026-56664

Published Jul 10, 2026·Updated Jul 18, 2026

NVD Description

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens from a trusted issuer to pass authentication. This issue is fixed in versions 3.4.12 and 4.15.2.

Affected Packages (1)

github.com/zitadel/zitadelGO
Fixed in 1.80.0-v2.20.0.20260615122908-fad02c6d9f45

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free