WhisperX tag archive

#token-rotation

This page collects WhisperX intelligence signals tagged #token-rotation. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Vault · 2026-04-26 23:54:22 · GitHub Issues

1. Refresh Token Rotation Gap Allows Session Hijacking via Replay Attack

A critical authentication vulnerability has been identified in the refresh token implementation. The system's token rotation mechanism fails to detect when a refresh token has already been reused, creating a window where a stolen token could be weaponized to maintain unauthorized access to a legitimate user's session. ...

The Lab · 2026-04-27 10:54:11 · GitHub Issues

2. Critical Refresh Token Rotation Flaw Allows Token Reuse After Legitimate Rotation

A critical security vulnerability in the `POST /auth/refresh` endpoint fails to invalidate refresh tokens after rotation, allowing intercepted tokens to remain functional even after legitimate users have already rotated them. The flaw undermines the fundamental security guarantee of refresh token rotation—a mechanism d...