GHSA-9hmg-827w-9rhj
MODERATECVE-2026-41164The v1 access token introspection endpoint (/auth/v1/introspectaccesstoken) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an active: true introspection response.
- Affected
- >=0
- Fixed in
- not stated
- Weakness
- CWE-345
- Published
- 2026-05-05
- Source
- osv