# OpenID private_key_jwt audience ambiguity

Source: https://startwithidentity.com/cves/cve-2025-27370/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

CVE-2025-27370 is the [OpenID Connect](https://startwithidentity.com/standards/openid-connect/) identifier for the same `private_key_jwt` audience ambiguity as [CVE-2025-27371](https://startwithidentity.com/cves/cve-2025-27371/). A client assertion is a [JWT](https://startwithidentity.com/glossary/jwt/). If `aud` is not a single, exact identifier for the intended authorization server, another server that knows the client's public key may accept it.

## Why it matters

OIDC deployments reuse OAuth client authentication. Multi-tenant SaaS IdPs and multi-region banks are the obvious victims: one environment's client JWT becomes another's. This is a protocol footgun, not a single product bug.

## What to do

- Same control as 27371: exact `aud`, per-environment keys, and a library that rejects surprising audiences.
- Review [FAPI](https://startwithidentity.com/glossary/fapi/) deployments first. They lean on `private_key_jwt` and sender-constrained tokens.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-27370](https://nvd.nist.gov/vuln/detail/CVE-2025-27370)
- OpenID Foundation disclosure
