CVE-2026-55735 – Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation
CVE ID :CVE-2026-55735 Published : Aug. 1, 2026, 7:16 p.m. | 43 minutes ago Description :Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim’s session with a forged token. Guardian.revoke/3 in lib decodes the…
