CVE-2026-63089: Bypass Token Expiration Check

Missing expiration time validation for a retrieved token, reducing the effectiveness of short-lived tokens and potentially enabling brute-force attacks.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-63089-bypass-token-expiration-check --engine opengrep

Description

Missing expiration time validation for a retrieved token, reducing the effectiveness of short-lived tokens and potentially enabling brute-force attacks.