CVE-2026-18165 - @fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies
Brief
CVE ID : CVE-2026-18165
Published : Aug. 15, 2026, 2:17 p. m.
- 6 hours, 49 minutes ago
Description : @fastify/oauth2 is an OAuth 2. 0 plugin for Fastify. In versions from 7.
- 0 up to but not including 8.
- 0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the flow.
Any party able to write a cookie for the application's host, such as a sibling subdomain under the same registrable domain, can plant matching state and verifier cookies and complete an attacker-owned OAuth flow inside a victim's browser, silently signing the victim in to the attacker's account (login CSRF). It does not expose the victim's own account, credentials, or tokens. The issue is fixed in @fastify/oauth2 8.
3.
