ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips expiration handling when an incoming token omits the exp claim, allowing a token from a trusted issuer to be treated as valid without an automatic expiration window. This issue is fixed in versions 3.4.12 and 4.15.2.
References
Configurations
No configuration.
History
10 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 18:16
Updated : 2026-07-10 19:17
NVD link : CVE-2026-56665
Mitre link : CVE-2026-56665
CVE.ORG link : CVE-2026-56665
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
