Skip to content

OAuth2 Authorization Server accepts malformed PKCE code challenges #19845

Description

@gtaylor-exactsciences

Describe the bug

Spring Authorization Server accepts malformed S256 code_challenge values at the authorization endpoint. With an authenticated user, a challenge that is too short or contains an invalid character results in an authorization code. With an anonymous user, a too-short challenge proceeds to the login redirect. This is not a a PKCE bypass.

To Reproduce

Clone the sample below and run mvn test. It uses Spring Boot 4.1.1, which manages Spring Security 7.1.1, and the default authorization server configuration. The suite has one passing valid-challenge control and three failing malformed-challenge assertions.

Expected behavior

Reject a malformed code_challenge as invalid_request during authorization request validation, regardless of whether the user is authenticated. Rejection should happen before either issuing a code or redirecting to login.

RFC 7636 §4.2 defines the challenge’s length and allowed characters. RFC 6749 §4.1.1 places request validation before user authentication, and §4.1.2.1 defines invalid_request for an invalid parameter value. The Spring Security 7.1.1 challenge validator checks presence and method, but not challenge length or characters.

Sample

Spring-Auth-Server-PKCE-Challenge-Validation-Repro

I’m happy to contribute a fix and tests if desired.

Acknowledgement: AI coding assistance was used in preparing this report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions