OAuth 2.0 Attack Chains: iss+sub Confusion, redirect_uri Path Traversal, and Token Leakage via Referer
OAuth 2.0 and OpenID Connect (OIDC) are so common now that they fade into the background. “Sign in with Google,” enterprise SSO, partner integrations, mobile apps requesting API access, underneath, it’s almost always OAuth. That ubiquity has a side effect: OAuth bugs keep appearing in real production systems,