JWT Verification Flaw in NeuVector by NeuVector
CVE-2026-78426
3.7LOW
What is CVE-2026-78426?
The NeuVector JWT verifier is susceptible to a vulnerability that allows noncanonical Base64URL encodings of the RSA signature field. This flaw enables an attacker with a valid but expired JWT, who has been logged out, to exploit their access by using the same non-expired token. This exploitation can persist with various canonical representations of the RSA signature field until the token's validity ultimately expires, posing significant risks to the security of the affected system.
Affected Version(s)
neuvector 0
