#JWT
All CosmicBytez Labs articles tagged #JWT, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-102268: PyJWT is_pem_format PEM Validation Bypass
A PEM-detection gap in PyJWT lets mutated public-key PEMs slip past its HMAC guard, enabling JWT signature forgery.
- Security
MStore API Plugin: Unauthenticated JWT Forgery Auth Bypass
Missing signature verification in MStore API's Firebase phone-auth handler lets attackers forge JWTs and impersonate any WordPress account.
- Security
Omnivore API: JWT Algorithm Confusion in Apple Sign-In Enables Account Takeover (CVE-2026-82454)
CVE-2026-82454 (CVSS 9.1): a JWT alg-confusion bug in Omnivore's Apple sign-in lets attackers forge tokens and take over any linked account.
- Security
CVE-2026-52539: Hardcoded JWT Secret in Outstatic CMS Enables Admin Takeover
Outstatic CMS versions up to and including 2.1.9 ship a publicly known default JWT signing secret, allowing unauthenticated attackers to forge valid admin...
- Security
CVE-2026-49352: 9Router Hardcoded JWT Secret Allows Complete Authentication Bypass
A critical CVSS 9.8 vulnerability in 9Router versions 0.2.21–0.4.43 exposes a hardcoded fallback JWT secret in source code, enabling attackers to forge...
- Security
CVE-2026-53471: migration-planner JWT Source ID Claim Not Validated in Agent API
A critical improper authentication vulnerability (CVSS 9.6) in Red Hat's migration-planner agent-API middleware allows authenticated agents to update...
- Security
CVE-2025-57735: Apache Airflow JWT Token Not Invalidated on Logout
A critical CVSS 9.1 vulnerability in Apache Airflow fails to invalidate JWT tokens upon user logout, allowing intercepted tokens to be reused for...
- Security
CVE-2026-1114: lollms JWT Weak Secret Key Allows Admin
A critical vulnerability (CVSS 9.8) in parisneo/lollms v2.1.0 allows attackers to brute-force the application's JWT secret key offline, forge...
- Security
CVE-2026-31946: Critical JWT Signature Verification Bypass
OpenOlat versions 10.5.4 through 20.2.4 fail to verify JWT signatures in their OpenID Connect implicit flow, allowing unauthenticated attackers to...