CVE-2026-49852

Description

A flaw was found in the joserfc Python library. A remote attacker can exploit a vulnerability in the joserfc.jwt.decode function to forge HMAC-signed tokens. This occurs because the library accepts tokens signed with an empty or null verification key, allowing an attacker to bypass integrity checks. Successful exploitation could lead to an integrity compromise of data processed by the library.

Statement

CVE-2026-49852 is an integrity/authentication bypass in the joserfc Python library (CWE-347): joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the verification key is an empty string or None, allowing an attacker to forge valid-looking JWTs. It is fixed in joserfc 1.6.8. Red Hat rates this Important, consistent with the upstream/CVEORG assessment.

joserfc is bundled by a number of Red Hat product and services container images. Version triage against the fixed version (1.6.8) shows only two shipping components carried a vulnerable joserfc (1.6.5) and are marked Affected: OpenShift Virtualization (CNV) 4.22 (ocp-virt-validation-checkup) and OpenShift Dedicated / hosted control planes (ask-sre). All other Red Hat components that bundle joserfc ship 1.6.8 or later (1.7.1-1.7.4) and are Not Affected because the vulnerable code is not present. The Red Hat Hardened Images (Hummingbird) jaeger package shipped an affected joserfc (1.6.7) and has already been remediated (rebuilt with joserfc 1.7.1, HUM-4648).

Mitigation

This flaw is only exploitable when an application invokes joserfc.jwt.decode with an empty-string or None verification key. Ensuring a valid, non-empty key is always supplied to JWT verification prevents exploitation. Upgrading joserfc to 1.6.8 or later fully remediates the flaw regardless of how the verification key is supplied.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/AN/A
Attack VectorNetworkN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredNoneN/AN/A
User InteractionNoneN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityNoneN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Understanding the Weakness (CWE)

Access Control,Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands

An attacker could gain access to sensitive data and possibly execute unauthorized code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.