CVE-2026-71575None▾ SunlitThe max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authenticati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54547Medium· 5.3On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
CVE-2026-107721Medium· 5.9fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107719Medium· 4.2fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107275Medium· 6.8@fastify/jwt is a JSON Web Token plugin for the Fastify web framework
CVE-2025-62781Medium· 5.0PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
CVE-2025-61775NoneVickey is a Misskey-based microblogging platform