PT-2026-63357 · N8N · N8N

·

CVE-2026-65599

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.64 n8n versions prior to 2.29.8 n8n versions prior to 2.30.1
Description Instances configured with a Google Service Account key mistakenly place the full PEM private key in the kid field of the JWT header, which is intended only for a key identifier. Because JWT headers are Base64-encoded and not encrypted, the private key can be recovered by any system that logs or inspects the JWT. An attacker with access to this key could impersonate the service account to access or modify authorized Google Cloud resources. This issue only affects instances using Google Service Account credentials.
Recommendations Update to version 1.123.64 or later. Update to version 2.29.8 or later. Update to version 2.30.1 or later. Avoid using Google Service Account credentials until the instance is patched. Rotate any Google Service Account keys used with an affected version. Review proxy, load balancer, and application logs for JWT headers containing exposed key material and treat those keys as compromised.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65599
GHSA-9R8P-H6CC-6QHM
GHSA-MHVH-GWHR-76PW

Affected Products

N8N