OIDC Nonce Validation Bypass in Logto by Logto.io
CVE-2026-15612
Currently unrated
What is CVE-2026-15612?
The vulnerability allows Logto to bypass OpenID Connect (OIDC) nonce validation when the nonce claim is not included in the id_token. This oversight could enable malicious actors to replay authentication tokens, effectively compromising session binding and raising concerns about the integrity of user sessions.
Affected Version(s)
Logto 1.10.1 <= 1.37.1
