<Vulnerability name="CVE-2026-81829">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-17T13:10:22</PublicDate>
    <Bugzilla id="2524980" url="https://bugzilla.redhat.com/show_bug.cgi?id=2524980" xml:lang="en:us">
smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: Unauthenticated same-origin SSRF via unsanitized JWT kid header in AwsAlbKeyResolver
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.
    </Details>
    <Statement xml:lang="en:us">
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it can be remotely triggered without authentication or user interaction but is limited to same-origin SSRF with read-only impact on the configured key endpoint host. Successful exploitation allows an attacker to force the application server to issue GET requests to arbitrary paths on the same origin, potentially reading non-public data exposed on that host. The vulnerability's root cause is a lack of input sanitization of the JWT kid header value before it is concatenated into the key-fetch URL in AwsAlbKeyResolver.
    </Statement>
    <Acknowledgement xml:lang="en:us">
This issue was discovered by Sandipan Roy (Red Hat).
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:exploit_intelligence:0">
        <ProductName>Exploit Intelligence</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>exploit-intelligence/agent-client-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:apicurio_registry:3">
        <ProductName>Red Hat build of Apicurio Registry 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>quarkus-smallrye-jwt</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:apicurio_registry:3">
        <ProductName>Red Hat build of Apicurio Registry 3</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>smallrye-jwt</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:8">
        <ProductName>Red Hat JBoss Enterprise Application Platform 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>smallrye-jwt</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>smallrye-jwt</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-81829
https://nvd.nist.gov/vuln/detail/CVE-2026-81829
    </References>
</Vulnerability>