# Duende OAuth token management mixes tokens across requests

Source: https://startwithidentity.com/cves/cve-2025-26620/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Duende's OAuth token-management package for .NET had a race: two concurrent requests could swap [access tokens](https://startwithidentity.com/glossary/access-token/). The token is valid. It is just not yours. Patched by Duende.

## Why it matters

This is the same class as [Okta's Java SDK race](https://startwithidentity.com/cves/cve-2025-67505/) (CVE-2025-67505). Identity SDKs that cache tokens in static or scoped objects will eventually leak a session across users under load. The bug report looks like "flaky auth." The incident looks like a customer seeing another customer's data.

## What to do

- Upgrade the Duende token-management package.
- Do not store tokens in a singleton without a per-user key. Load tests should assert that user A never receives user B's `sub`.
- Prefer sender-constrained tokens ([DPoP](https://startwithidentity.com/glossary/dpop/), mTLS) so a mixed token is useless on the wrong client.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-26620](https://nvd.nist.gov/vuln/detail/CVE-2025-26620)
