# OAuth 2.0 private_key_jwt audience ambiguity

Source: https://startwithidentity.com/cves/cve-2025-27371/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

The OpenID Foundation disclosed that the [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/) JWT client-authentication profile (`private_key_jwt`) leaves the audience value underspecified. A client assertion minted for authorization server A can be accepted by authorization server B if both share a view of the client's key and neither pins `aud` tightly. CVE-2025-27371 is the OAuth-spec ID. [CVE-2025-27370](https://startwithidentity.com/cves/cve-2025-27370/) is the OpenID twin.

There is no single vendor patch. The fix is in the spec text and in how implementations validate `aud`.

## Why it matters

`private_key_jwt` is the "grown-up" client authentication. Banks, FAPI deployments, and high-assurance [CIAM](https://startwithidentity.com/glossary/ciam/) stacks use it specifically to avoid shared secrets. An audience mix-up turns that strength into a confused-deputy: a JWT meant for one environment or tenant is a valid login somewhere else.

## What to do

- Pin `aud` to the exact authorization-server identifier (issuer or token-endpoint URL) your implementation now documents. Reject arrays that include extra values.
- Separate client keys per environment and per tenant. Shared keys make the spec ambiguity exploitable.
- Track the OpenID Foundation and IETF errata. This is a spec-level CVE, so library defaults will lag.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-27371](https://nvd.nist.gov/vuln/detail/CVE-2025-27371)
- OpenID Foundation disclosure on private_key_jwt audience
