OIDC Nonce Validation Bypass in Logto by Logto.io
CVE-2026-15612

Currently unrated

Key Information:

Vendor

Logto

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-15612?

The vulnerability allows Logto to bypass OpenID Connect (OIDC) nonce validation when the nonce claim is not included in the id_token. This oversight could enable malicious actors to replay authentication tokens, effectively compromising session binding and raising concerns about the integrity of user sessions.

Affected Version(s)

Logto 1.10.1 <= 1.37.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.