CVE-2026-31813Disclosure(supabase / auth)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using specially crafted ID tokens when the Apple or Azure providers are enabled. The attacker issues a valid, asymmetrically signed ID token from their issuer for each victim email address, which then is sent to the Supabase Auth token endpoint using the ID token flow. If the ID token is OIDC compliant, the Auth server would validate it against the attacker-controlled issuer and link the existing OIDC identity (Apple or Azure) of the victim to an additional OIDC identity based on the ID token contents. The Auth server would then issue a valid user session (access and refresh tokens) at the AAL1 level to the attacker. This vulnerability is fixed in 2.185.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • auth

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
auth

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-05-20: 1Technical Details · 2026-05-20: 103-1205-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-122
Disclosure1General1
2026-05-201
Disclosure1
Full discourse3 posts
  • SUNJOYcs@SunjoYcs
    Disclosure

    Supabase auth (pre-2.185.0) accepted oidc tokens from attacker-controlled issuers if the signature was valid. CVE-2026-31813 Real test: do you verify the issuer matches the expected provider, or only that the jwt signature is valid? Those are different checks.

    Post summary

    The post discloses that Supabase auth versions before 2.185.0 accept OIDC tokens from attacker-controlled issuers when only the JWT signature is verified, but it does not provide an exploit, patch, or evidence of active exploitation.

    1004021
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-31813 Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue ses… https://www.cve.org/CVERecord?id=CVE-2026-31813 ----- Traducción: CVE-2026-31813 Sup… http://infoflow.cloud`

    Post summary

    The tweet briefly announces CVE‑2026‑31813, links to its CVE record, but offers no additional technical, exploit, or mitigation details.

    0000033
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31813 Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue ses… https://www.cve.org/CVERecord?id=CVE-2026-31813

    Post summary

    The entry announces a new CVE (2026-31813) affecting Supabase Auth’s JWT handling before version 2.185.0, but provides no PoC, exploit code, active exploitation, or patch details.

    00000260
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsupabaseauth---

Explore more