CVE Explorer
CVE-2026-44699
LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JWT without knowing any secret or RSA private key. This is an algorithm-confusion authentication bypass. It affects applications that load RSA keys from JWKS where alg is omitted, which is valid JWK syn
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-327","description":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"libjwt","vendor":"benmcollins","versions":[{"status":"affected","version":">= 3.0.0, < 3.3.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.1,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-327","description":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/benmcollins/libjwt/security/advisories/GHSA-q843-6q5f-w55g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/adp/0/references/0
{"name":"https://github.com/benmcollins/libjwt/security/advisories/GHSA-q843-6q5f-w55g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/benmcollins/libjwt/security/advisories/GHSA-q843-6q5f-w55g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e43cd0a33f7ad6ba85a69b85c6283b170b9ea30337c3e8cce2a0c756540c8643 · sha256:d383c56744336a83… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.