« Volver al listado

CVE-2026-34240

Estado: AnalizadaAlta (7.5)—

JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store.

Leer descripción completaMostrar menos

Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matching private key. Applications using affected versions for token verification are impacted. This issue has been patched in version 0.3.5+1. A workaround for this issue involves rejecting tokens where header jwk is present unless that jwk matches a key already present in the application's trusted key store.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en validación de tokens JWT/JWS (CWE-347) explotable remotamente sin autenticación (AV:N, PR:N, UI:N) permitiendo falsificar tokens por clave en header. Impacto: suplantación de identidad (T1553.006) y acceso a recursos autenticados.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34240",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34240",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-01T14:02:31.709988Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "appsup-dart",
          "product": "jose",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.3.5+1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-31T16:16:33.090",
  "references": [
    {
      "url": "https://github.com/appsup-dart/jose/commit/b07799aac1f56a9a21483feac026272aab30cc5d",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/appsup-dart/jose/security/advisories/GHSA-vm9r-h74p-hg97",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matching private key. Applications using affected versions for token verification are impacted. This issue has been patched in version 0.3.5+1. A workaround for this issue involves rejecting tokens where header jwk is present unless that jwk matches a key already present in the application's trusted key store."
    },
    {
      "lang": "es",
      "value": "JOSE es una biblioteca de Javascript Object Signing and Encryption (JOSE). Antes de la versión 0.3.5+1, una vulnerabilidad en jose podría permitir a un atacante remoto no autenticado falsificar tokens JWS/JWT válidos utilizando una clave incrustada en el encabezado JOSE (jwk). La vulnerabilidad existe porque la selección de claves podría tratar el jwk proporcionado en el encabezado como un candidato de verificación incluso cuando esa clave no estaba presente en el almacén de claves de confianza. Dado que los encabezados JOSE son entrada no confiable, un atacante podría explotar esto creando una carga útil de token, incrustando una clave pública controlada por el atacante en el encabezado y firmando con la clave privada correspondiente. Las aplicaciones que utilizan versiones afectadas para la verificación de tokens se ven afectadas. Este problema ha sido parcheado en la versión 0.3.5+1. Una solución alternativa para este problema implica rechazar los tokens donde el jwk del encabezado está presente a menos que ese jwk coincida con una clave ya presente en el almacén de claves de confianza de la aplicación."
    }
  ],
  "lastModified": "2026-07-24T20:10:00.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:appsup-dart:jose:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "900F124C-8D70-47CF-BE74-3D47A796AB50",
              "versionEndExcluding": "0.3.5\\+1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}