Executive brief
Rodauth is a Ruby authentication framework used to secure web applications. An attacker with access to a temporary JWT access token can bypass authentication by sending it to the refresh endpoint using non-POST methods, obtaining a new valid token indefinitely without providing a refresh token. This enables persistent account access even after the original token expires.
Technical details
The vulnerability exists in the jwt_refresh route where new JWT access tokens are issued without proper validation of the HTTP method. An attacker can present an access token to the refresh route via GET or other non-POST methods to obtain a new valid access token. The root cause is insufficient enforcement of POST-method requirements and missing validation that a valid refresh token must be provided. The attack requires only network access to the vulnerable endpoint and possession of a temporary access token. The fix, available in version 2.47.0 and later, removes the Authorization response header from responses to non-POST requests or requests that do not accept JSON, preventing token issuance in these cases.
Affected products
- Jeremy Evans Rodauth before 2.47.0
Timeline
- 2026-08-29: disclosed