Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g2qj-prgh-4g9r | Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback |
Wed, 22 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nhost nhost\/auth
|
|
| CPEs | cpe:2.3:a:nhost:nhost\/auth:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nhost nhost\/auth
|
|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nhost
Nhost nhost |
|
| Vendors & Products |
Nhost
Nhost nhost |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer headers, and proxy/CDN logs. Note that the refresh token is one-time use and all of these leak vectors are on owned infrastructure or services integrated by the application developer. This vulnerability is fixed in 0.48.0. | |
| Title | Nhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callback | |
| Weaknesses | CWE-200 CWE-598 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T16:00:25.296Z
Reserved: 2026-03-31T19:38:31.616Z
Link: CVE-2026-34969
Updated: 2026-04-07T15:47:28.542Z
Status : Analyzed
Published: 2026-04-06T16:16:38.457
Modified: 2026-04-22T20:16:14.793
Link: CVE-2026-34969
No data.
OpenCVE Enrichment
Updated: 2026-04-07T09:39:17Z
Github GHSA