CVE-2026-55669
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.2 / 10
Vulnerability Description
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
go
Product
github.com/zitadel/zitadel
External References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-g5h5-m4hm-xjrr
- https://github.com/zitadel/zitadel/commit/d184e976fc799a383bb6ef9f32c3bae11a3ef85f
- https://github.com/zitadel/zitadel/releases/tag/v3.4.12
- https://github.com/zitadel/zitadel/releases/tag/v4.15.2
- https://github.com/advisories/GHSA-g5h5-m4hm-xjrr
Discussion (0)
Add Comment
No comments yet. Be the first!