How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

OAuth mix-up attacks and RFC 9207: The issuer check that never made it to token exchange

calendar_today July 20, 2026 domain workos

A four-year-old fix for a classic OAuth attack closed one door. Token exchange left a nearly identical one open, and CVE-2026-59208 walked right through it.

open_in_new Read original post