CVE-2026-71575EPSS p12.3%

CVE-2026-71575CVE-2026-71575

Description

The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Scoring

EPSS0.23% probability of exploitation · percentile 12.3% · 2026-10-10T12:00:23Z
Last modified2026-10-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.