Junglewise Threat Intelligence

ZITADEL insufficient session expiration in JWT IdP Provider

Severity: medium · CVSS 4.2 · Published 2026-06-18

Technologies: github.com/zitadel/zitadel (Go), ZITADEL. Vendors: Go, ZITADEL.

Executive brief

ZITADEL, an identity management platform, was found to have a flaw in how it validates security tokens from external providers. If a login token is missing specific expiration timestamps, the system treats it as valid forever. This could allow an attacker with a stolen or specially crafted token to maintain permanent, unauthorized access to a user's account without the session ever timing out.

Technical details

Two vulnerabilities exist in ZITADEL's external JWT Identity Provider (IdP) validation pipeline. First, if a JWT omits the 'exp' (expiration) claim, the system skips expiration enforcement and treats the token as valid indefinitely. Second, the 'iat' (issued-at) claim check, which enforces a 1-hour freshness window, is only performed if the claim is present; if missing, the check is bypassed. An attacker with a token lacking these claims can maintain a permanent session. This violates OIDC Core 1.0 specifications regarding session integrity. Patches are available in versions 3.4.12 and 4.15.2.

Affected products

  • ZITADEL ZITADEL 3.0.0 to 3.4.11, 4.0.0 to 4.15.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory
  • 2026-06-18: patched

References

Related threats