Skip to content
CodeAuditAgent

CVE-2026-88819

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

Weakness

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.