Beveiligingsadvies

CVE-2026-55669

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-10 16:58:46
Laatst bijgewerkt 2026-07-10 18:16:52
Toegewezen door GitHub_M
CVSS-score 4.2
Status PUBLISHED

Beschrijving

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.