4.2
CVE-2026-56664
- EPSS 0.2%
- Veröffentlicht 10.07.2026 17:21:22
- Zuletzt bearbeitet 10.07.2026 19:17:26
- CVE-Watchlists
- Unerledigt
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens from a trusted issuer to pass authentication. This issue is fixed in versions 3.4.12 and 4.15.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerzitadel
≫
Produkt
zitadel
Version
>= 4.0.0-rc.1, < 4.15.2
Status
affected
Version
< 3.4.12
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.103 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://github.com/zitadel/zitadel/releases/tag/v3.4.12
https://github.com/zitadel/zitadel/releases/tag/v4.15.2
https://github.com/zitadel/zitadel/security/advisories/GHSA-wxg7-w2v3-w38g
https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8
https://github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551ac