JWT Verification Flaw in NeuVector by NeuVector
CVE-2026-78426

3.7LOW

Key Information:

Vendor

Go

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-78426?

The NeuVector JWT verifier is susceptible to a vulnerability that allows noncanonical Base64URL encodings of the RSA signature field. This flaw enables an attacker with a valid but expired JWT, who has been logged out, to exploit their access by using the same non-expired token. This exploitation can persist with various canonical representations of the RSA signature field until the token's validity ultimately expires, posing significant risks to the security of the affected system.

Affected Version(s)

neuvector 0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.