
BREAKING: CVE-2026-18165 affects @fastify/oauth2 7.2.0 through 8.2.0. A related host that can set cookies for the app can plant OAuth state and PKCE verifier values, then complete an attacker-owned login inside a victim browser. This is login CSRF. It does not expose the victim's own account or OAuth tokens. Details: https://hol.org/blog/cve-2026-18165-fastify-oauth2-login-csrf
Post summary
CVE-2026-18165 is a login CSRF flaw in Fastify's OAuth2 plugin that allows attackers to plant OAuth state and PKCE verifier cookies, facilitating hijacked logins, but it does not expose user tokens, and no patches, exploits, or active exploitation reports are mentioned.



