PT-2026-94341 · Unknown · Smallrye Jwt

·

CVE-2026-81829

·

Published

2026-09-17

·

Updated

2026-09-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SmallRye JWT (affected versions not specified)
Description A flaw exists in the AwsAlbKeyResolver of SmallRye JWT, used for verifying JSON Web Tokens signed by AWS Application Load Balancers. When the AWS ALB key provider is active, the resolver builds the key-fetch URL by concatenating the kid header value from an incoming JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to trigger GET requests to arbitrary paths on the same origin as the configured key endpoint, potentially exposing non-public endpoints or internal data before the JWT signature is verified. This is a Server-Side Request Forgery (SSRF), where the server is tricked into making requests to its own internal resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81829

Affected Products

Smallrye Jwt