Improper Cryptographic Signature Verification in Guardian by ueberauth
CVE-2026-55735
What is CVE-2026-55735?
The Guardian by ueberauth is susceptible to a vulnerability that allows unauthenticated attackers to revoke legitimate sessions using a forged JSON Web Token (JWT). This flaw arises from improper verification of the JWT's cryptographic signature during the revocation process, specifically in the revoke/3 function. An attacker can exploit this by creating a JWT with the right claim values and submit it, circumventing the signature check, which can lead to the unauthorized termination of a victim's session. This poses a significant risk to user session integrity and application security.
Affected Version(s)
guardian 1.0.0 < 2.4.1
guardian d65227145f72b290106c06cecbe42728fbf05fe2 < 2bd7a8c29770d423d855c0a4965caa6c3e486901
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
