Sensitive Data Exposure in Boruta Authorization Server by Malach IT
CVE-2026-55221
6.5MEDIUM
What is CVE-2026-55221?
The Boruta Authorization Server, designed for OAuth 2.0 and OpenID Connect implementations, has an issue where sensitive values like access tokens and authorization codes were previously logged in business event logs. This created a risk for exposure, allowing unauthorized access to sensitive tokens by individuals with access to the logs or log aggregation systems. The issue has been addressed in version 0.10.0, which ensures that such sensitive information is no longer logged, thereby improving security for users relying on Boruta for authorization.
Affected Version(s)
boruta-server < 0.10.0
