In certain IETF OAuth 2.0-related specifications, when the JSON Web...
Vulnerability Description
In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs may include RFC 7523, and also RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27371
Credits & Attribution
No credits recorded in the NVD database.
References
- https://openid.net/wp-content/uploads/2025/01/OIDF-Responsible-Disclosure-Notice-on-Security-Vulnerability-for-private_key_jwt.pdf
- https://openid.net/notice-of-a-security-vulnerability/
- https://talks.secworkshop.events/osw2025/talk/R8D9BS/
- https://github.com/OWASP/ASVS/issues/2678
- https://eprint.iacr.org/2025/629
More from IETF
View All →Affected Vendor
IETF
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.