Bug 2501881 (CVE-2026-49852)
| Summary: | CVE-2026-49852 joserfc: joserfc: Integrity bypass via forged HMAC-signed tokens | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anpicker, anthomas, bparees, dfreiber, dkeler, drow, dschmidt, ebourniv, ehelms, ggainey, hasun, ilpinto, jburrell, jfula, jlanda, jowilson, jpasqual, juwatts, jwong, kaycoth, kshier, ltomasbo, mdellweg, mhayden, mhulan, nmoumoul, nyancey, omaciel, ometelka, osousa, pcreech, ptisnovs, rchan, rjohnson, sbunciak, sdoran, simaishi, smallamp, stcannon, suppawar, syedriko, teagle, thason, tmalecek, ttakamiy, vkumar, xdharmai, yguenane, ykashtan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the joserfc Python library. A remote attacker can exploit a vulnerability in the `joserfc.jwt.decode` function to forge HMAC-signed tokens. This occurs because the library accepts tokens signed with an empty or null verification key, allowing an attacker to bypass integrity checks. Successful exploitation could lead to an integrity compromise of data processed by the library.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-17 20:02:05 UTC
|