4.2
CVE-2026-56665
- EPSS 0.17%
- Veröffentlicht 10.07.2026 17:22:46
- Zuletzt bearbeitet 10.07.2026 19:17:26
- CVE-Watchlists
- Unerledigt
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips expiration handling when an incoming token omits the exp claim, allowing a token from a trusted issuer to be treated as valid without an automatic expiration window. This issue is fixed in versions 3.4.12 and 4.15.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerzitadel
≫
Produkt
zitadel
Version
>= 4.0.0-rc.1, < 4.15.2
Status
affected
Version
< 3.4.12
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://github.com/zitadel/zitadel/releases/tag/v3.4.12
https://github.com/zitadel/zitadel/releases/tag/v4.15.2
https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8
https://github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551ac
https://github.com/zitadel/zitadel/security/advisories/GHSA-v77h-2w3m-94hx