Flaw in jwcrypto Library Affects JavaScript Object Signing and Encryption
CVE-2026-84185

5.9MEDIUM

What is CVE-2026-84185?

A coding flaw in the jwcrypto library, utilized for JavaScript Object Signing and Encryption (JOSE) standards, allows unauthorized access. Specifically, the library mishandles key ID verification when validating General JSON Serialization JWS with a key set. This mistake may lead to incorrect acceptance of signatures from any valid key, enabling malicious users possessing a valid key to bypass authorization checks in applications that depend on the key ID for authenticating tenants or users.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.