Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-78426

LOW NVD
CVSS Score 3.7
Severity LOW
Published Sep 17, 2026
Vendor unknown

Description

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.

References