Moderate severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-56664
Description
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens from a trusted issuer to pass authentication. This issue is fixed in versions 3.4.12 and 4.15.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/zitadel/zitadelGo | < 1.80.0-v2.20.0.20260615122908-fad02c6d9f45 | 1.80.0-v2.20.0.20260615122908-fad02c6d9f45 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-wxg7-w2v3-w38gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-56664ghsaADVISORY
- github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8ghsax_refsource_MISCWEB
- github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551acghsax_refsource_MISCWEB
- github.com/zitadel/zitadel/commit/fad02c6d9f4587956f830d4536c64a9a94baa7acghsaWEB
- github.com/zitadel/zitadel/releases/tag/v3.4.12ghsax_refsource_MISCWEB
- github.com/zitadel/zitadel/releases/tag/v4.15.2ghsax_refsource_MISCWEB
- github.com/zitadel/zitadel/security/advisories/GHSA-wxg7-w2v3-w38gghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.