CVE-2026-49852
Description
A flaw was found in the joserfc Python library. A remote attacker can exploit a vulnerability in the joserfc.jwt.decode function to forge HMAC-signed tokens. This occurs because the library accepts tokens signed with an empty or null verification key, allowing an attacker to bypass integrity checks. Successful exploitation could lead to an integrity compromise of data processed by the library.
Statement
CVE-2026-49852 is an integrity/authentication bypass in the joserfc Python library (CWE-347): joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the verification key is an empty string or None, allowing an attacker to forge valid-looking JWTs. It is fixed in joserfc 1.6.8. Red Hat rates this Important, consistent with the upstream/CVEORG assessment.
joserfc is bundled by a number of Red Hat product and services container images. Version triage against the fixed version (1.6.8) shows only two shipping components carried a vulnerable joserfc (1.6.5) and are marked Affected: OpenShift Virtualization (CNV) 4.22 (ocp-virt-validation-checkup) and OpenShift Dedicated / hosted control planes (ask-sre). All other Red Hat components that bundle joserfc ship 1.6.8 or later (1.7.1-1.7.4) and are Not Affected because the vulnerable code is not present. The Red Hat Hardened Images (Hummingbird) jaeger package shipped an affected joserfc (1.6.7) and has already been remediated (rebuilt with joserfc 1.7.1, HUM-4648).
Mitigation
This flaw is only exploitable when an application invokes joserfc.jwt.decode with an empty-string or None verification key. Ensuring a valid, non-empty key is always supplied to JWT verification prevents exploitation. Upgrading joserfc to 1.6.8 or later fully remediates the flaw regardless of how the verification key is supplied.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | None | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | High | N/A | N/A |
| Availability Impact | None | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Understanding the Weakness (CWE)
Access Control,Integrity,Confidentiality
Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands
An attacker could gain access to sensitive data and possibly execute unauthorized code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.