Beveiligingsadvies

CVE-2026-78426

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-17 09:28:19
Laatst bijgewerkt 2026-09-17 12:40:32
Toegewezen door suse
CVSS-score 3.7
Status PUBLISHED

Beschrijving

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.