Payload authentication token field handling issue
Critical severity
GitHub Reviewed
Published
Sep 18, 2026
in
payloadcms/payload
•
Updated Oct 7, 2026
Package
Affected versions
>= 3.0.0, < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Patched versions
3.90.0
4.0.0-canary.34
Description
Published by the National Vulnerability Database
Oct 6, 2026
Published to the GitHub Advisory Database
Oct 7, 2026
Reviewed
Oct 7, 2026
Last updated
Oct 7, 2026
Impact
Under certain field configurations, Payload could include unintended values in the authentication token issued at login.
You are affected if:
Patches
Payload now restricts which field configuration options can influence the contents of the authentication token.
Users should upgrade payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Workarounds
There is no complete workaround. Users should upgrade payload packages to
>= 3.90.0or>= 4.0.0-canary.34.References