CVE-2025-31123 Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
CVE-2025-31123 Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
CVE-2025-31123 Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
CVE-2025-31123 Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
CVE-2025-31123 Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of ...

Continue Reading
Important: grafana security update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang-jwt/jwt: jwt-go allows excessive memory allocation ...

Continue Reading
CVE-2025-2559 Org.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloak

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, f ...

Continue Reading
CBL Mariner 2.0 Security Update: application-gateway-kubernetes-ingress / azcopy / cert-manager / coredns / etcd / influxdb / packer (CVE-2024-51744)

The version of application-gateway-kubernetes-ingress / azcopy / cert-manager / coredns / etcd / influxdb / packer installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, there ...

Continue Reading

Back to Main

Subscribe for the latest news: