目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-81829— Smallrye-JWT 未认证同域SSRF漏洞

一分钟漏洞结论

影响对象
Red Hat Exploit Intelligence
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 SmallRye JWT 的 中发现一个缺陷,该解析器被应用程序用于验证由 AWS 应用负载均衡器(AWS ALB)签名的 JSON Web Token(JWT)。当配置了 密钥提供者时,解析器在构建获取密钥的 URL 时,直接拼接了入站 JWT 中由攻击者控制的 头部值,但未对路径遍历字符或查询字符串分隔符进行过滤或规范化处理。这使得未认证的远程攻击者能够迫使应用服务器向已配置密钥端点所在的同一源上的任意路径发起 GET 请求。其结果是,攻击者可以在 JWT 签名验证执行之前,读取该源上可访问的非公开端点或内

CVSS 5.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-81829 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver
来源: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat Exploit Intelligence - cpe:/a:redhat:exploit_intelligence:0
Red Hat Red Hat build of Apicurio Registry 3 - cpe:/a:redhat:apicurio_registry:3
Red Hat Red Hat build of Apicurio Registry 3 - cpe:/a:redhat:apicurio_registry:3
Red Hat Red Hat build of Quarkus - cpe:/a:redhat:quarkus:3
Red Hat Red Hat build of Quarkus - cpe:/a:redhat:quarkus:3
Red Hat Red Hat JBoss Enterprise Application Platform 8 - cpe:/a:redhat:jboss_enterprise_application_platform:8
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp

二、漏洞 CVE-2026-81829 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-81829 的情报信息

登录查看更多情报信息。

CVE-2026-81829 厂商安全公告 (1)

CVE-2026-81829 其他参考 (1)

同批安全公告 · Red Hat · 2026-09-17 · 共 7 条

CVE-2026-86320 7.8 HIGH Flatpak-builder 远程代码执行漏洞
CVE-2026-87742 7.5 HIGH Quarkus-websockets-next 消息缓冲拒绝服务漏洞
CVE-2026-76781 5.5 MEDIUM libxml2 nextcatalog空指针解引用漏洞
CVE-2026-92904 4.3 MEDIUM foreman_remote_execution 作业输出未授权读取
CVE-2026-92893 4.3 MEDIUM foreman_ansible API 权限绕过漏洞
CVE-2026-92894 4.3 MEDIUM Foreman_ansible 越权删除查找值漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-81829

暂无评论


发表评论