
🚨 HIGH: CVE-2026-59096 (CVSS 7.5) - Dapr Sentry OIDC discovery endpoint vulnerable to Host header poisoning. Attackers can serve malicious JWKS, accepting forged JWTs. Patch immediately if OIDC enabled without jwt-issuer/oidc-allowed-hosts configured. #CVE #PatchNow https://t.co/OyfYLm0YUZ
Post summary
The tweet warns about CVE-2026-59096, a Host header poisoning flaw in Dapr Sentry's OIDC discovery endpoint, and urges users to patch immediately when OIDC is enabled without proper host restrictions.
