Unrated severityNVD Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2026-71575
CVE-2026-71575
Description
The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: before 4.2.4, 4.1.9, or 3.6.13
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.