# Zitadel JWT auth grant ignores key expiration

Source: https://startwithidentity.com/cves/cve-2025-31123/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[Zitadel](https://startwithidentity.com/vendors/open-source/zitadel/) accepted a JWT authorization grant without checking that the signing key was still inside its validity window. A key you thought you had retired still authenticated the client. The project shipped a patch.

## Why it matters

Key expiration is how you contain a leaked machine credential. If the [IdP](https://startwithidentity.com/glossary/identity-provider/) ignores `exp` on the key (not just on the token), rotation is theater. Open-source IdPs are in a lot of homelab-to-production paths. This is a control you assume exists.

## What to do

- Upgrade Zitadel to the patched release.
- Rotate any JWT grant keys that were valid across the vulnerable window, even if they are "expired" in the UI.
- Confirm your other IdPs ([Keycloak](https://startwithidentity.com/vendors/open-source/keycloak/), [authentik](https://startwithidentity.com/vendors/open-source/authentik/)) actually enforce key expiry, not only token expiry.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-31123](https://nvd.nist.gov/vuln/detail/CVE-2025-31123)
