CVE-2026-73683
Laravel Socialite Facebook Provider Authentication Bypass via Replayed OIDC ID Tokens.
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
Laravel Socialite's Facebook provider has an authentication bypass vulnerability. Attackers can replay captured OIDC id_tokens to gain unauthorized access to user accounts because the nonce claim is not validated. This issue impacts the security of user account access.