Executive brief
ZITADEL, an identity management platform, was found to have a flaw in how it validates security tokens from external providers. If a login token is missing specific expiration timestamps, the system treats it as valid forever. This could allow an attacker with a stolen or specially crafted token to maintain permanent, unauthorized access to a user's account without the session ever timing out.
Technical details
Two vulnerabilities exist in ZITADEL's external JWT Identity Provider (IdP) validation pipeline. First, if a JWT omits the 'exp' (expiration) claim, the system skips expiration enforcement and treats the token as valid indefinitely. Second, the 'iat' (issued-at) claim check, which enforces a 1-hour freshness window, is only performed if the claim is present; if missing, the check is bypassed. An attacker with a token lacking these claims can maintain a permanent session. This violates OIDC Core 1.0 specifications regarding session integrity. Patches are available in versions 3.4.12 and 4.15.2.
Affected products
- ZITADEL ZITADEL 3.0.0 to 3.4.11, 4.0.0 to 4.15.1
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory
- 2026-06-18: patched
References
- https://api.github.com/users/Android-Login-Analysis
- https://github.com/Android-Login-Analysis
- https://api.github.com/users/Android-Login-Analysis/gists%7B/gist_id%7D
- https://api.github.com/users/Android-Login-Analysis/repos
- https://avatars.githubusercontent.com/u/43461385?v=4
- https://api.github.com/users/Android-Login-Analysis/events%7B/privacy%7D