CVE-2026-34240
JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store.
Leer descripción completaMostrar menos
Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matching private key. Applications using affected versions for token verification are impacted. This issue has been patched in version 0.3.5+1. A workaround for this issue involves rejecting tokens where header jwk is present unless that jwk matches a key already present in the application's trusted key store.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1553.006Code Signing Policy Modificationdefense impairment90 % - Impacto secundario
T1578Modify Cloud Compute Infrastructuredefense impairment60 %
Vulnerabilidad en validación de tokens JWT/JWS (CWE-347) explotable remotamente sin autenticación (AV:N, PR:N, UI:N) permitiendo falsificar tokens por clave en header. Impacto: suplantación de identidad (T1553.006) y acceso a recursos autenticados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-347
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34240",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34240",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-01T14:02:31.709988Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "appsup-dart",
"product": "jose",
"versions": [
{
"status": "affected",
"version": "< 0.3.5+1"
}
]
}
]
}
],
"published": "2026-03-31T16:16:33.090",
"references": [
{
"url": "https://github.com/appsup-dart/jose/commit/b07799aac1f56a9a21483feac026272aab30cc5d",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/appsup-dart/jose/security/advisories/GHSA-vm9r-h74p-hg97",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-347"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matching private key. Applications using affected versions for token verification are impacted. This issue has been patched in version 0.3.5+1. A workaround for this issue involves rejecting tokens where header jwk is present unless that jwk matches a key already present in the application's trusted key store."
},
{
"lang": "es",
"value": "JOSE es una biblioteca de Javascript Object Signing and Encryption (JOSE). Antes de la versión 0.3.5+1, una vulnerabilidad en jose podría permitir a un atacante remoto no autenticado falsificar tokens JWS/JWT válidos utilizando una clave incrustada en el encabezado JOSE (jwk). La vulnerabilidad existe porque la selección de claves podría tratar el jwk proporcionado en el encabezado como un candidato de verificación incluso cuando esa clave no estaba presente en el almacén de claves de confianza. Dado que los encabezados JOSE son entrada no confiable, un atacante podría explotar esto creando una carga útil de token, incrustando una clave pública controlada por el atacante en el encabezado y firmando con la clave privada correspondiente. Las aplicaciones que utilizan versiones afectadas para la verificación de tokens se ven afectadas. Este problema ha sido parcheado en la versión 0.3.5+1. Una solución alternativa para este problema implica rechazar los tokens donde el jwk del encabezado está presente a menos que ese jwk coincida con una clave ya presente en el almacén de claves de confianza de la aplicación."
}
],
"lastModified": "2026-07-24T20:10:00.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:appsup-dart:jose:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "900F124C-8D70-47CF-BE74-3D47A796AB50",
"versionEndExcluding": "0.3.5\\+1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}