在 SmallRye JWT 的 中发现一个缺陷,该解析器被应用程序用于验证由 AWS 应用负载均衡器(AWS ALB)签名的 JSON Web Token(JWT)。当配置了 密钥提供者时,解析器在构建获取密钥的 URL 时,直接拼接了入站 JWT 中由攻击者控制的 头部值,但未对路径遍历字符或查询字符串分隔符进行过滤或规范化处理。这使得未认证的远程攻击者能够迫使应用服务器向已配置密钥端点所在的同一源上的任意路径发起 GET 请求。其结果是,攻击者可以在 JWT 签名验证执行之前,读取该源上可访问的非公开端点或内
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Exploit Intelligence | - |
cpe:/a:redhat:exploit_intelligence:0
|
|
| Red Hat | Red Hat build of Apicurio Registry 3 | - |
cpe:/a:redhat:apicurio_registry:3
|
|
| Red Hat | Red Hat build of Apicurio Registry 3 | - |
cpe:/a:redhat:apicurio_registry:3
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-87742 | 7.5 HIGH | Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded |
| CVE-2026-92925 | 7.1 HIGH | Redis: redis: out-of-bounds read via crafted cluster bus packets |
| CVE-2026-76781 | 5.5 MEDIUM | Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92893 | 4.3 MEDIUM | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, expo |
| CVE-2026-92894 | 4.3 MEDIUM | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value d |
No comments yet