Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33996

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the jwk2key tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

A flaw was found in LibJWT, a C JSON Web Token Library. When parsing JSON Web Key (JWK) files for RSA-PSS, the library did not correctly handle cases where NULL values were encountered instead of expected string values. An attacker could exploit this vulnerability by providing a specially crafted JWK file containing integers in fields that anticipate strings. This could lead to a denial of service, impacting the availability of systems using the affected library.

Отчет

The LibJWT is only shipped with community products. The 2.x series and before of LibJWT does not have JWK parsing, so they are not affected.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2452531LibJWT: LibJWT: Denial of Service via crafted JSON Web Key (JWK) files

EPSS

Процентиль: 5%
0.0015
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
5 месяцев назад

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

CVSS3: 5.5
nvd
5 месяцев назад

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

CVSS3: 5.5
debian
5 месяцев назад

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and pr ...

EPSS

Процентиль: 5%
0.0015
Низкий

5.9 Medium

CVSS3