Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45363

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

A flaw was found in ruby-jwt, a Ruby implementation of the RFC 7519 OAuth JSON Web Token (JWT) standard. A remote attacker can exploit this vulnerability by crafting a malicious token that is accepted due to an empty key being used in the HMAC (Hash-based Message Authentication Code) digest calculation during token verification. This allows the attacker to bypass authentication and integrity checks, potentially leading to unauthorized access or data manipulation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImageschunkahAffected
Red Hat Satellite 6rubygem-jwtAffected
Red Hat Satellite 6satellite-capsule:el8/rubygem-jwtAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2500739ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification

EPSS

Процентиль: 15%
0.00242
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

CVSS3: 9.1
nvd
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

CVSS3: 9.1
debian
20 дней назад

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token ...

CVSS3: 7.4
github
3 месяца назад

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

CVSS3: 7.4
fstec
3 месяца назад

Уязвимость реализации стандарта JWT Ruby JWT, связанная с недостатками процедуры аутентификации, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00242
Низкий

7.4 High

CVSS3