CVE-2025-66432 Overview
CVE-2025-66432 affects the Oxide control plane versions 15 through 17 before 17.1. API tokens in the affected releases can be renewed past their expiration date, allowing authenticated users to extend token lifetimes beyond the intended validity window. The issue is categorized under [CWE-420] (Unprotected Alternate Channel) and carries a network attack vector with low privileges required.
Critical Impact
Authenticated users can prolong API token validity beyond expiration, undermining token lifetime controls and expanding the window in which compromised tokens remain usable.
Affected Products
- Oxide control plane version 15
- Oxide control plane version 16
- Oxide control plane version 17 (before 17.1)
Discovery Timeline
- 2025-11-30 - CVE-2025-66432 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66432
Vulnerability Analysis
The Oxide control plane provides an API token mechanism to authenticate programmatic requests. Tokens are issued with an expiration timestamp that bounds their usable lifetime. In releases 15 through 17 prior to 17.1, the renewal path fails to verify that the token has not already expired before extending its validity.
An authenticated caller can invoke the renewal operation and receive an extended lifetime for a token that should no longer be honored. This weakens the integrity guarantee that expired credentials cannot be reused. The vulnerability does not affect confidentiality or availability, but it does affect the integrity of the token lifecycle enforced by the control plane.
Root Cause
The root cause is missing enforcement of the token expiration state during renewal. The renewal path treats an expired token as a candidate for extension rather than rejecting it. Details of the code change are visible in the Omicron repository comparison referenced in the vendor advisory.
Attack Vector
Exploitation requires network access to the control plane API and valid low-privilege credentials. The attacker submits a renewal request against a token whose expiration has already elapsed. The control plane returns a new, extended expiration, restoring the token's ability to authenticate subsequent API calls. See the Oxide Security Advisory 20251117-1 for vendor details.
No verified public proof-of-concept code is available. The vulnerability mechanism is described in prose based on the vendor advisory.
Detection Methods for CVE-2025-66432
Indicators of Compromise
- API token renewal events on tokens whose stored expiration timestamp is earlier than the renewal request time.
- Tokens whose cumulative lifetime, calculated across renewal events, exceeds the configured maximum.
- Successful API authentications using token identifiers previously observed as expired.
Detection Strategies
- Audit control plane logs for token renew operations and correlate them with the token's issued and expiration timestamps.
- Alert on any renewal where the request timestamp exceeds the token expiration timestamp.
- Baseline normal token renewal cadence per user or service account and flag deviations.
Monitoring Recommendations
- Ingest Oxide control plane audit logs into a centralized log platform for retention and correlation.
- Track per-token lifetime metrics and generate reports on tokens exceeding policy-defined maximum age.
- Review privileged and service-account token usage regularly for anomalous renewal patterns.
How to Mitigate CVE-2025-66432
Immediate Actions Required
- Upgrade the Oxide control plane to version 17.1 or later, which contains the fix referenced in the vendor advisory.
- Inventory all active API tokens issued by affected control plane versions and identify any with anomalous renewal history.
- Revoke and reissue tokens suspected of having been renewed past their original expiration.
Patch Information
Oxide released the fix in control plane version 17.1. Refer to Oxide Security Advisory 20251117-1 and the corresponding Omicron code changes for the authoritative patch details. Additional vendor information is available at the Oxide Computer homepage.
Workarounds
- Reduce the maximum allowable token lifetime through operational policy until the upgrade is applied.
- Rotate API tokens on a shorter cadence and disable automated renewal for high-privilege service accounts.
- Restrict network access to the control plane API to trusted management networks to limit exposure of the renewal endpoint.
# Example: list and revoke API tokens using the Oxide CLI
# Consult official Oxide documentation for exact command syntax
oxide auth token list
oxide auth token revoke --id <TOKEN_ID>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.