GHSA-j4j7-8j5c-5hxwMediumCVSS 6.3
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue...
🔗 CVE IDs covered (1)
📋 Description
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-16206
- https://github.com/django-oauth/django-oauth-toolkit/issues/1715
- https://github.com/django-oauth/django-oauth-toolkit
- https://vuldb.com/cve/CVE-2026-16206
- https://vuldb.com/submit/857897
- https://vuldb.com/submit/857923
- https://vuldb.com/vuln/380022
- https://vuldb.com/vuln/380022/cti
- https://github.com/advisories/GHSA-j4j7-8j5c-5hxw