PT-2026-54957 · Liboauth2 · Liboauth2

·

CVE-2026-54430

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions liboauth2 versions prior to 2.3.0
Description An issue exists in the oauth2 jose jwks aws alb resolve() function where the AWS ALB verifier processes the signer and kid values from an unverified JWT header. When the signer matches the configured ARN, the kid is appended to the alb base url without URL encoding or path sanitization. Because the HTTP GET request is issued before the signature is verified, a remote attacker can trigger a Server-Side Request Forgery (SSRF), forcing the server to send a GET request to an internal path of the attacker's choosing.
Recommendations Update to version 2.3.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91679
CVE-2026-54430

Affected Products

Liboauth2