CVE-2025-31123
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2025-31123 is a vulnerability affecting Zitadel, an open-source identity infrastructure software. The issue arises from a failure to verify the expiration date of JSON Web Tokens (JWT) keys used in Authorization Grants. This flaw allows an attacker with an expired key to retrieve valid access tokens, potentially leading to unauthorized access. However, it is important to note that the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints remains unaffected, as these endpoints correctly reject expired keys. The vulnerability has been addressed in several Zitadel releases, including 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Zitadel