OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-105863: Payload authentication token field handling issue

GitHub Advisories · officialPublished Oct 7, 2026Risk 50/100

### Impact Under certain field configurations, Payload could include unintended values in the authentication token issued at login. You are affected if: - You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name. ### Patches Payload now restricts which field configuration options can influence the contents of the authentication token. Users should upgrade payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ### Workarounds There is no complete workaround. Users should upgrade payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`.

Upgrade affected packages to a patched version: payload 3.90.0, payload 4.0.0-canary.34.

Vendor
Not specified
Product
payload
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source