← Back to CVE List
CVE-2026-78426NVD
Vulnerability Summary
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
CVSS v3.1 Base Metrics — Score 3.7 (LOW)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- go neuvector <= v5.6.1
- go neuvector v5.6.1