Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kazlu

#29157of 57,338
9.3Total CVSS
Vulnerabilities · 1
PT-2026-97797
9.3
2026-09-24
Unknown · Nimble Zta · CVE-2026-91187
**Name of the Vulnerable Software and Affected Versions** nimble zta versions 0.1.2 through 0.1.2 **Description** Improper verification of cryptographic signatures in the Cloudflare Zero Trust authentication strategy allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. The `verify token/2` function in `lib/nimble zta/cloudflare.ex` incorrectly handles the result of `JOSE.JWT.verify/2` by discarding the boolean verification result and returning the decoded token even after a failed signature check. An attacker can exploit this by sending a forged JSON Web Token (JWT) in the `cf-access-jwt-assertion` header containing the expected `iss` claim and seven service token claims. Because `verify iss/2` reads the `iss` claim from the forged token without validation, the system accepts the forged claims as a legitimate authenticated identity. **Recommendations** Update nimble zta to version 0.1.3. As a temporary workaround, disable the Cloudflare authentication strategy. Alternatively, manually reject requests if the JWT in the `cf-access-jwt-assertion` header contains both the `common name` and `type` claims before calling the `NimbleZTA.Cloudflare.authenticate/3` function.