Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54430

Опубликовано: 02 июл. 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0

A flaw was found in liboauth2 in the oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB JWT verifier reads the signer and kid fields from the unverified JWT header. When signer matches the configured ARN, kid is appended to the ALB base URL without path sanitization, and an HTTP GET request is issued before signature verification. An attacker who can present a crafted JWT to an endpoint using AWS ALB verification could force the server to issue GET requests to unintended internal paths, potentially disclosing limited information from internal services.

Отчет

This Moderate flaw in liboauth2 allows for Server-Side Request Forgery (SSRF) when an application uses AWS ALB JWT verification. An attacker can craft a JWT to force the server to make GET requests to internal network paths, potentially exposing limited internal service information. This requires the vulnerable component to be configured with AWS ALB JWT verification.

Меры по смягчению последствий

Restrict network access to the application endpoint that processes AWS ALB-signed JWTs to trusted sources only. If the AWS ALB verification feature (oauth2_jose_jwks_aws_alb_resolve) is not required, disable it in the liboauth2 configuration. Upgrade to liboauth2 version 2.3.0 or later to fully resolve this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2496465liboauth2: liboauth2: Server-Side Request Forgery allows unauthorized internal network access

EPSS

Процентиль: 2%
0.00121
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0

nvd
около 1 месяца назад

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0

debian
около 1 месяца назад

liboauth2 is vulnerable to Server-Side Request Forgery inoauth2_jose_j ...

github
около 1 месяца назад

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0

EPSS

Процентиль: 2%
0.00121
Низкий

5.8 Medium

CVSS3