CVE-2026-71206: Go-Shiori Shiori

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase.

Affected products

Published 2026-08-05. Last modified 2026-08-26.