Junglewise Threat Intelligence

CVE-2026-59096: Dapr Sentry OIDC discovery document injection via X-Forwarded-Host

CVE-2026-59096 · Severity: high · CVSS 7.5 · Published 2026-07-02

Executive brief

Dapr Sentry, a component used for managing security identities in distributed applications, contains a flaw in its identity discovery service. An attacker can trick the system into trusting a malicious server for security credentials by sending a specially crafted web request. This could allow the attacker to bypass security checks and gain unauthorized access to services that rely on Dapr for authentication.

Technical details

Dapr Sentry's OIDC discovery endpoint (/.well-known/openid-configuration) incorrectly trusts the X-Forwarded-Host header when deriving the 'issuer' and 'jwks_uri' fields. This occurs by default when no 'oidc-allowed-hosts' or 'jwt-issuer' is explicitly configured. An unauthenticated remote attacker can send a request with a malicious X-Forwarded-Host header to poison the discovery document, which is served with a one-hour public cache lifetime. Consequently, relying parties performing dynamic discovery may fetch JSON Web Key Sets (JWKS) from an attacker-controlled server, leading to the acceptance of forged, attacker-signed JSON Web Tokens (JWTs). The issue is addressed in Dapr versions 1.17.8 and 1.18.x by ensuring X-Forwarded-Host is only honored when an explicit allowlist is configured.

Affected products

  • Dapr Dapr 1.17.0, 1.18.0

Timeline

  • 2026-05-27: patched: Initial fix PR submitted to Dapr master branch
  • 2026-07-02: disclosed: CVE-2026-59096 published

References