JWT Verification Vulnerability in PIA by Eclipse
CVE-2026-18353

8.8HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-18353?

The PIA application has a vulnerability in its /v1/upload/sbom endpoint, where it incorrectly processes unverified Bearer JWTs. The vulnerability lies in the way Python's urlparse function handles authority strings, allowing an attacker to craft a malicious issuer that circumvents the issuer allowlist check. As a result, the application may inadvertently connect to an arbitrary server chosen by the attacker for the retrieval of JWKS, potentially exposing sensitive data and compromising the security of the system.

Affected Version(s)

Eclipse CSI - PIA 0.4.0 < 0.6.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.