Exposure of Resource to Wrong Sphere Affecting steeltoe.security.authentication.openidconnect package, versions [,4.2.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-STEELTOESECURITYAUTHENTICATIONOPENIDCONNECT-17373298
  • published18 Jun 2026
  • disclosed18 Jun 2026
  • creditUnknown

Introduced: 18 Jun 2026

NewCVE-2026-50202  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade Steeltoe.Security.Authentication.OpenIdConnect to version 4.2.0 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere in the TokenKeyResolver function. An attacker can bypass authentication and gain unauthorized access by exploiting the shared static JWKS cache across multiple schemes, allowing a key fetched for one identity provider to validate tokens for another. This also enables the use of stale or revoked keys due to the lack of cache expiration.

Note:

This is only exploitable if multiple JwtBearer schemes are configured with different identity providers in the same application.

Workaround

This vulnerability can be mitigated by configuring only one JwtBearer scheme per application when different identity providers are required, and/or restarting the application process after an identity provider signing key rotation to clear stale cached keys.

CVSS Base Scores

version 4.0
version 3.1