CVE Vulnerabilities

CVE-2025-66432

Unprotected Alternate Channel

Published: Nov 30, 2025 | Modified: Nov 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Potential Mitigations

References