A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulatio…
Medium CVSS 6.3
Summary
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/django-oauth/django-oauth-toolkit/
- https://github.com/django-oauth/django-oauth-toolkit/issues/1715
- https://vuldb.com/cve/CVE-2026-16206
- https://vuldb.com/submit/857897
- https://vuldb.com/submit/857923
- https://vuldb.com/vuln/380022
- https://vuldb.com/vuln/380022/cti
Timeline
- nvd_ingest NVD