Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34969

29
FAUCET Score

Nhost, an open-source Firebase alternative featuring GraphQL capabilities, contains a critical authentication vulnerability affecting versions prior to 0.48.0. The OAuth provider callback flow exposes refresh tokens directly in redirect URL query parameters, creating multiple exposure vectors through browser history, server access logs, HTTP Referer headers, and proxy/CDN logs. Although refresh tokens are single-use, the exposure creates significant confidentiality risks across infrastructure and integrated services under developer control. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction, indicating broad exploitability. The attack has low complexity and results in high confidentiality impact with no integrity or availability concerns. The FAUCET Risk Score of 48.0/100 reflects elevated risk within the vulnerability landscape. The vulnerability shows no evidence of active exploitation and does not appear on the KEV catalog, suggesting limited real-world weaponization at present. However, its presence on the Active Hot List indicates ongoing community attention and monitoring. A patch is available in version 0.48.0, and organizations running vulnerable versions should prioritize upgrading immediately given the straightforward nature of token exposure through standard logging mechanisms.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.48.0CPE matchmatch criteria
cpe:2.3:a:nhost:nhost\/auth:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.3LOW

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 3rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/nhost/nhostFixed in: 0.0.0-20260330133707-294954e0fc3a

Vendor Advisories (1)

goGHSA-g2qj-prgh-4g9rlow

Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback

Apr 1, 2026

References

github.com / nhost/nhost/security/advisories/GHSA-g2qj-prgh-4g9r
ExploitMitigationVendor Advisory