Back to CVE List

CVE-2026-15612

Vulnerability Description

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Logto
Product
Logto

External References

Discussion (0)

Add Comment

No comments yet. Be the first!