CVE-2026-45363

Aliases:DEBIAN-CVE-2026-45363CGA-36j6-4cp6-cjwhCGA-6r3j-c4p9-jjx7CGA-74qf-m8q6-m36xCGA-jvhw-mv49-r7qrCGA-mm3x-xgjv-r7wjCGA-p74m-3fhj-fph3CGA-24rq-g25m-pmjxCGA-25qx-9v7r-m8h2CGA-2mjx-cf98-rffgCGA-33vc-mfxc-9jj7CGA-34vx-939p-wjr3CGA-3frg-fhgg-m6pqCGA-3qgh-xcgj-w4jxCGA-3qh6-qfhh-xqc8CGA-4xq6-24cx-mwqgCGA-55qm-2p5r-wwmmCGA-63p3-w792-pc33CGA-66q3-85mh-xr3xCGA-6pq5-f58c-72crCGA-738r-3wjj-2mwxCGA-7h48-8pmm-3rxqCGA-82m5-5gmr-r39fCGA-875q-h822-7983CGA-8mh3-94w7-3qj5CGA-8p75-8wmm-827jCGA-8wr6-mhfx-5g9vCGA-9c7h-gfvh-85pwCGA-9m3f-gc6q-9942CGA-c6pm-33g4-6qgqCGA-cg59-qrmx-qh3hCGA-cj9p-6476-fjhfCGA-f6wc-wvxc-hwcvCGA-fpgh-2rwq-jr48CGA-g782-3vg5-mrpxCGA-ghx6-q8p4-gmjrCGA-gjq3-j4xj-3797CGA-gmf9-4r5c-cx3xCGA-h5pm-j4m8-jfqwCGA-hfhc-hwp7-xw52CGA-hgvh-v2x5-7wxvCGA-hmmw-w637-62j2CGA-hpr2-5xfr-jw7rCGA-j572-66p2-5rr3CGA-jfwc-q984-54hvCGA-jj7p-f423-v75xCGA-m2gf-cx47-8c29CGA-m647-4cfj-7gj7CGA-mqc4-3f47-xc22CGA-mv94-j469-r9rvCGA-p82c-wpvc-j766CGA-pqvf-g786-j2m3CGA-prhf-xgp7-5738CGA-rf7h-89xh-pjf3CGA-v7fx-7j22-rfx6CGA-v7v9-2f5m-wgcvCGA-vm83-m5fx-pwc2CGA-w2gj-v6ch-gj88CGA-wv58-68qr-9r4q
Deferred
Published: 14 Jul 2026, 21:32
Last modified:15 Jul 2026, 13:26

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (cve.org)
EPSS Score
0.24% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 21:32
Published
Vulnerability first disclosed
15 Jul 2026, 13:26
Last Modified
Vulnerability information updated

Description

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.

CVSS Metrics

  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.24% Percentile: 16%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-326Inadequate Encryption Strength

    The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

  • CWE-1391Use of Weak Credentials

    The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Affected Systems

  • chainguardcinc-auditor

    < 7.1.7-r0

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    < 18.10.8-r0

  • chainguardgitlab-rails-ce-18.11

    < 18.11.5-r0

  • chainguardgitlab-rails-ce-18.3

    all

  • chainguardgitlab-rails-ce-18.4

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    < 19.0.2-r0

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    < 18.10.8-r0

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.5-r0

  • chainguardgitlab-rails-ce-fips-18.3

    all

  • chainguardgitlab-rails-ce-fips-18.4

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    < 19.0.1-r4

  • chainguardkube-fluentd-operator

    < 1.18.2-r65

  • chainguardlogstash-8.19

    < 8.19.16-r0

  • chainguardlogstash-8.19-iamguarded-compat

    < 8.19.16-r0

  • chainguardlogstash-8.19-with-output-opensearch

    < 8.19.16-r0

  • chainguardruby3.2-kube-logging-operator-fluentd-outputs

    < 6.5.2-r0

  • chainguardruby3.4-kube-logging-operator-fluentd-outputs

    < 6.5.2-r0

  • wolficinc-auditor

    < 7.1.7-r0

  • wolfikube-fluentd-operator

    < 1.18.2-r65

  • wolfiruby3.2-kube-logging-operator-fluentd-outputs

    < 6.5.2-r0

  • wolfiruby3.4-kube-logging-operator-fluentd-outputs

    < 6.5.2-r0

  • debianruby-jwt

    all | all | < 2.5.0-1+deb12u1 | all | < 3.2.0-1

  • jwtruby-jwt

    < 2.10.3 | ≥ 3.0.0, < 3.2.0

References (8)