Junglewise Threat Intelligence

CVE-2026-15612: Logto OIDC nonce validation bypass in OidcConnector

CVE-2026-15612 · Severity: info · Published 2026-07-23

Technologies: Logto. Vendors: Logto.

Executive brief

Logto, an open-source identity infrastructure and authentication service, contains a security flaw in how it verifies login requests. The system fails to properly validate a security token (nonce) if it is missing from the response, which could allow an attacker to reuse old authentication tokens. This weakens the security of user sessions and could potentially lead to unauthorized account access through session replay attacks.

Technical details

A vulnerability exists in Logto's OIDC Connector where the system fails to enforce nonce validation if the 'nonce' claim is missing from the ID token. This occurs within the OidcConnector utility logic. By omitting the nonce claim, an attacker can bypass the security check intended to ensure that an authentication response corresponds to a specific original request. This flaw facilitates replay attacks and weakens the binding between the user's session and the authentication event. The issue affects versions 1.10.1 through 1.37.1.

Affected products

  • Logto Logto 1.10.1 to 1.37.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats