CVE-2026-78426 - Logout bypass via alternate JWT spelling
CVE ID :CVE-2026-78426
Published : Sept. 17, 2026, 10:17 a.m. | 51 minutes ago
Description :The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 17, 2026, 10:17 a.m. | 51 minutes ago
Description :The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...