The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continu…
Low CVSS 3.7
Summary
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426
- https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j
Timeline
- nvd_ingest NVD