CVE-2026-48767: Unverified Oauth State Base64 Json Parsecve-2026-48767-unverified-oauth-state-base64-json-parse
OAuth state parameters are parsed directly from unauthenticated base64 JSON without cryptographic signature or nonce verification. An attacker can tamper with state fields to bypass authorization checks or conduct CSRF attacks.