CVE-2023-31580: Networknt Light-OAUTH2

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.

Affected products

  • Networknt Light-OAUTH2: before 2.1.27 (fixed in 2.1.27)

Published 2023-10-25. Last modified 2026-06-17.