Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45363

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

EPSS

Процентиль: 15%
0.00242
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
ubuntu
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

CVSS3: 7.4
redhat
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

CVSS3: 9.1
debian
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token ...

CVSS3: 7.4
github
3 месяца назад

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

CVSS3: 7.4
fstec
3 месяца назад

Уязвимость реализации стандарта JWT Ruby JWT, связанная с недостатками процедуры аутентификации, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00242
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287