Vulnerability CVE-2023-31580


Published: 2023-10-25

Description:
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.

 References:
https://github.com/networknt/light-oauth2/issues/369
https://github.com/KANIXB/JWTIssues/blob/main/Certification%20Verification%20issue%20in%20light-oauth2.md

Copyright 2026, cxsecurity.com

 

Back to Top