CVE-2026-34969
EUVD-2026-1935806.04.2026, 16:16
Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer headers, and proxy/CDN logs. Note that the refresh token is one-time use and all of these leak vectors are on owned infrastructure or services integrated by the application developer. This vulnerability is fixed in 0.48.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nhost | nhost\/auth | 𝑥 < 0.48.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration