nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token in github.com/nuts-foundation/nuts-node
{ "url": "https://pkg.go.dev/vuln/GO-2026-5291", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-5291.json"