CVE-2026-34969
HIGHNhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callback
Title source: cnaDescription
Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer headers, and proxy/CDN logs. Note that the refresh token is one-time use and all of these leak vectors are on owned infrastructure or services integrated by the application developer. This vulnerability is fixed in 0.48.0.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/nhost/nhost/security/advisories/GHSA-g2qj-prgh-4g9r
Scores
CVSS v3
7.5
EPSS
0.0027
EPSS Percentile
18.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
CWE-598
Status
published
Products (3)
nhost/nhost
0 - 0.0.0-20260330133707-294954e0fc3aGo
nhost/nhost
< 0.48.0
nhost/nhost\/auth
< 0.48.0
Published
Apr 06, 2026
Tracked Since
Apr 06, 2026