Beveiligingsadvies

CVE-2026-15612

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-23 15:45:27
Laatst bijgewerkt 2026-07-27 16:37:08
Toegewezen door certcc
CVSS-score 9.1
Status PUBLISHED

Beschrijving

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.