What is CVE-2026-55735?
CVE-2026-55735 is an improper cryptographic signature verification vulnerability in the ueberauth guardian library. It allows an unauthenticated attacker to revoke a victim's session using a forged token due to the insecure use of the `peek` function without signature verification. Affected systems should update the library or ensure secure invocation of the `revoke` function.
Azərbaycanca: CVE-2026-55735 'ueberauth guardian' kitabxanasında kriptoqrafik imza yoxlanışının düzgün aparılmamasıdır. Bu zəiflik autentifikasiya olunmamış hücumçuya saxta tokenlə istifadəçinin sessiyasını ləğv etməyə imkan verir. Kitabxanadan istifadə edən sistemlərdə 'guardian' yenilənməli və ya `revoke` funksiyasının təhlükəsiz çağırışı təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What can an attacker achieve by exploiting CVE-2026-55735?
An unauthenticated attacker can revoke a victim's session using a forged token.
What measures should be taken to mitigate CVE-2026-55735?
The ueberauth guardian library should be updated, or secure invocation of the `revoke` function must be ensured.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.