Bug 2496465 (CVE-2026-54430)
| Summary: | CVE-2026-54430 liboauth2: liboauth2: Server-Side Request Forgery allows unauthorized internal network access | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in liboauth2 in the oauth2_jose_jwks_aws_alb_resolve()
function. The AWS ALB JWT verifier reads the signer and kid fields from
the unverified JWT header. When signer matches the configured ARN, kid is
appended to the ALB base URL without path sanitization, and an HTTP GET
request is issued before signature verification. An attacker who can
present a crafted JWT to an endpoint using AWS ALB verification could
force the server to issue GET requests to unintended internal paths,
potentially disclosing limited information from internal services.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2496724 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-02 11:01:34 UTC
|