Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75509

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3.

A flaw was found in joserfc, a Python library for JSON Object Signing and Encryption (JOSE) standards. A remote attacker could exploit a vulnerability in the JWTClaimsRegistry by crafting a JSON Web Token (JWT) with an array-valued issuer (iss) claim. This flaw allows the attacker to bypass the intended issuer validation, potentially leading to impersonation or unauthorized access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-sandbox-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat Enterprise Linux command line assistantrhel-cla/rhel-knowledge-bridge-rhel10Fix deferred
Red Hat Hardened ImagesjaegerNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/ocp-virt-validation-checkup-rhel9Fix deferred
Red Hat Satellite 6satellite/foreman-mcp-server-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-480
https://bugzilla.redhat.com/show_bug.cgi?id=2523102joserfc: joserfc: Issuer-validation bypass via array-valued claims

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3.

CVSS3: 6.5
nvd
24 дня назад

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3.

CVSS3: 6.5
debian
24 дня назад

joserfc is a Python library that provides an implementation of several ...

6.5 Medium

CVSS3