{"record":{"id":"82e28b352ae27aa3","repo":"google-gemini/gemini-cli","slug":"error-issuer-mismatch-possible-oauth-mix-up-attack","errorCode":null,"errorMessage":"Error: Issuer mismatch - possible OAuth mix-up attack.","messagePattern":"Error: Issuer mismatch - possible OAuth mix-up attack\\.","errorType":"http","errorClass":null,"httpStatus":400,"severity":"error","filePath":"packages/core/src/utils/oauth-flow.ts","lineNumber":297,"sourceCode":"                    <p>Error: Missing issuer parameter in response.</p>\n                    <p>You can close this window.</p>\n                  </body>\n                </html>\n              `);\n                server.close();\n                reject(\n                  new Error(\n                    'Missing \"iss\" parameter in authorization response per RFC 9207',\n                  ),\n                );\n                return;\n              }\n\n              if (!areIssuersEqual(iss, expectedIssuer)) {\n                debugLogger.error(\n                  'OAuth callback rejected: Issuer mismatch between authorization response and expected authorization server. Possible IdP mix-up attack (RFC 9207).',\n                );\n                res.writeHead(400, { 'Content-Type': 'text/html' });\n                res.end(`\n                <html>\n                  <body>\n                    <h1>Authentication Failed</h1>\n                    <p>Error: Issuer mismatch - possible OAuth mix-up attack.</p>\n                    <p>You can close this window.</p>\n                  </body>\n                </html>\n              `);\n                server.close();\n                reject(\n                  new Error(\n                    'Issuer mismatch in authorization response - possible OAuth mix-up attack',\n                  ),\n                );\n                return;\n              }\n              debugLogger.debug(","sourceCodeStart":279,"sourceCodeEnd":315,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/utils/oauth-flow.ts#L279-L315","documentation":"The iss parameter in the OAuth callback does not equal the expected issuer (after issuer-normalization comparison), signaling a possible OAuth mix-up attack where the response came from a different authorization server than the one the request was sent to. The server logs the mismatch, closes, and the flow is rejected.","triggerScenarios":"Thrown at packages/core/src/utils/oauth-flow.ts:297 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Correct the configured issuer URL to match the provider's actual issuer exactly","Check for multiple configured providers sharing one redirect URI (mix-up scenario)","Restart the flow against the intended provider"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}