<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-oauth-rfc7523bis" target="https://datatracker.ietf.org/doc/html/draft-ietf-oauth-rfc7523bis-09">
   <front>
      <title>Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and Assertion-Based Authorization Grants</title>
      <author initials="M. B." surname="Jones" fullname="Michael B. Jones">
         <organization>Self-Issued Consulting</organization>
      </author>
      <author initials="B." surname="Campbell" fullname="Brian Campbell">
         <organization>Ping Identity</organization>
      </author>
      <author initials="C." surname="Mortimore" fullname="Chuck Mortimore">
         <organization>Disney</organization>
      </author>
      <author initials="F." surname="Skokan" fullname="Filip Skokan">
         <organization>Okta</organization>
      </author>
      <date month="April" day="16" year="2026" />
      <abstract>
	 <t>   This document updates RFC7521, RFC7522, RFC7523 and RFC9126 with
   respect to the treatment of audience values in OAuth 2.0 Client
   Assertion Authentication and Assertion-based Authorization Grants to
   address a security vulnerability identified in the previous
   requirements for those audience values in multiple OAuth 2.0
   specifications.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-oauth-rfc7523bis-09" />
   
</reference>
