Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-90012
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
spi: Fix DMA mapping ownership on partial map failure

In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a later transfer, mappings created for earlier transfers remain active. In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they are assigned only after every transfer has been mapped. The subsequent spi_unmap_msg() may therefore unmap the TX mapping again or release earlier mappings using a NULL or stale device. Using a NULL device can trigger an oops. An empty SG table does not prevent the NULL dereference because dma_unmap_sg_attrs() accesses the device before checking the entry count. Publish both mapping devices before mapping starts and unwind all failures through __spi_unmap_msg(). This clears the mapping flags and releases each mapping once with the device that created it. Publishing the devices before the loop also refreshes them when no transfer needs mapping. No mapping flag is set in that case, so current users do not use the pointers as mapping owners.

Affected products

Linux
  • =<7.2.*
  • <a38051fa2ddedbc8ec15292c55e276880ec5b9a4
  • ==6.11
  • =<6.12.*
  • <cc8354213ad6bd5fb8cc05a3fa3701188d086626
  • <5def8b6aaad44603740786262b95b6f77df52a1c
  • =<6.18.*
  • <6.11
  • =<*
  • <367cea239fc93094e5c16a72724800e0358f5c46
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
iio: light: ltrf216a: fix runtime PM reference leak in error path

In the Linux kernel, the following vulnerability has been resolved: iio: light: ltrf216a: fix runtime PM reference leak in error path ltrf216a_get_lux() acquires a runtime PM reference by calling ltrf216a_set_power_state(data, true). However, if ltrf216a_read_data() fails, the function returns immediately without dropping the reference. This leaves the runtime PM usage count unbalanced, preventing the device from autosuspending after a failed read. Fix this by releasing the runtime PM reference before returning from the error path.

Affected products

Linux
  • =<7.2.*
  • <80e7381e8cccb543397572af153865f34aaf4353
  • <0614928a3eda35bddd8c2f02311e286b59bbe746
  • =<6.12.*
  • <c4f003d8578f5718fe1ec332bc89f9ff69fd205b
  • <c132aef0e757a39036b1d40faf0569f2e343b13e
  • =<6.18.*
  • =<*
  • ==6.1
  • <6.1
Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
samples/damon/wsse: handle damon_start() failure

In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure Patch series "samples/damon: handle damon_{start,stop}() failures". All DAMON sample modules are not correctly handling failures from damon_start(). Among those, mtier also has an additional problem for handling of damon_stop() failures. wsse and prcl also have a problem in their damon_call() failure handling. As a result, memory leaks, next DAMON operation disruptions, and use-after-free can happen. Fix those. Note that only the damon_start() failure caused issues can reliably be reproduced. Reproducing those issues require the admin permission, though. This patch (of 6): damon_sample_wsse_start() callers assume it will clean up resources when it fails. And the function does the cleanup for context buildup failures. However, it is not doing the cleanup for damon_start() failure. As a result, when damon_start() fails, it leaks the memory for DAMON context. Free the context in case of the failure to fix the issues. Note that the issue can reliably be reproduced because the module calls damon_start() in the exclusive mode. For example, $ sudo damo start $ echo $$ | sudo tee /sys/module/damon_sample_wsse/parameters/target_pid $ echo Y | sudo tee /sys/module/damon_sample_wsse/parameters/enabled $ sudo cat /proc/allocinfo | grep damon_new_ctx Because the first command is running another DAMON instance, the third command fails the damon_start() call because the new DAMON instance cannot exclusively run. And without this fix, by repeating the third and the fourth commands above, we can show the memory consumption is only increasing due to the leaks. It requires the sudo permission though. The issue was discovered [1] by Sashiko.

Affected products

Linux
  • =<7.2.*
  • <e4742be45ea45bf554399ce89a09f71e525d7981
  • =<6.18.*
  • <6.14
  • <6179c7f47876d576dfe30efa8fbf1b0b1fdd13c0
  • ==6.14
  • =<*
  • <e60774d6335b89fac0be8b17a041fcffc508d281
Dismissed
(no matching packages found)
Permalink CVE-2026-73167
8.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary OS commands as root via crafted request parameters.

Affected products

EKI-1242EIMS
  • =<1.06.01
EKI-1242IEIMS
  • =<1.06.01
Dismissed
(no matching packages found)
Permalink CVE-2026-20332
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Affected products

Cisco Secure Firewall Management Center (FMC)
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.7.12
  • ==7.2.8.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.2.10.1
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.6.3
  • ==10.0.1
  • ==7.2.2
  • ==7.2.4
  • ==7.2.0.1
  • ==7.2.9
  • ==7.2.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.2.6
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.5
  • ==7.4.2.2
  • ==7.2.3.1
  • ==7.2.5.2
  • ==7.2.3
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.0.0
  • ==7.6.4
  • ==7.2.10
  • ==10.0.0
  • ==7.0.6.2
  • ==7.4.6
  • ==7.2.11
  • ==7.6.2
  • ==7.2.0
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.2.5
  • ==7.0.6
  • ==7.2.8
  • ==7.0.7
  • ==7.4.3
  • ==7.7.11
  • ==7.2.7
  • ==7.3.1.2
  • ==7.6.5
  • ==7.2.10.2
  • ==7.2.5.1
  • ==7.4.1
  • ==7.4.1.1
  • ==7.2.4.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software
  • ==7.6.2.1
  • ==7.4.2.1
  • ==7.0.9
  • ==7.0.4
  • ==7.3.1
  • ==7.6.0
  • ==7.4.2.3
  • ==7.0.3
  • ==7.0.5
  • ==7.7.0
  • ==7.0.6.1
  • ==7.4.4
  • ==7.7.10.1
  • ==7.0.8
  • ==7.0.6.3
  • ==7.6.1
  • ==7.4.2.4
  • ==7.4.0
  • ==7.4.2.2
  • ==7.7.10
  • ==7.0.1
  • ==7.0.2
  • ==7.3.1.1
  • ==7.6.4
  • ==10.0.0
  • ==7.0.6.2
  • ==7.6.2
  • ==7.0.1.1
  • ==7.0.8.1
  • ==7.0.2.1
  • ==7.0.6
  • ==7.7.11
  • ==7.0.7
  • ==7.4.3
  • ==7.3.1.2
  • ==7.4.1
  • ==7.4.1.1
  • ==7.4.2
  • ==7.3.0
  • ==7.4.7
  • ==7.0.0.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • ==9.22.2
  • ==9.18.4.47
  • ==9.16.3.14
  • ==9.16.4.55
  • ==9.22.2.14
  • ==9.23.1.22
  • ==9.20.4.19
  • ==9.18.4.68
  • ==9.16.4.71
  • ==9.23.1.19
  • ==9.19.1.42
  • ==9.23.1.32
  • ==9.18.4.5
  • ==9.18.1.3
  • ==9.22.1.6
  • ==9.20.4.22
  • ==9.20.3
  • ==9.18.4.67
  • ==9.18.4.24
  • ==9.18.4.53
  • ==9.22.2.13
  • ==9.24.1.221
  • ==9.20.4.30
  • ==9.23.1.211
  • ==9.18.2.7
  • ==9.18.4
  • ==9.16.4.18
  • ==9.22.1.2
  • ==9.20.1.5
  • ==9.23.1.26
  • ==9.16.4.61
  • ==9.16.4.92
  • ==9.18.4.29
  • ==9.22.2.9
  • ==9.24.1.9
  • ==9.18.4.57
  • ==9.18.3.55
  • ==9.18.2.5
  • ==9.23.1.13
  • ==9.16.2.13
  • ==9.20.3.4
  • ==9.16.3
  • ==9.22.2.20
  • ==9.23.1.195
  • ==9.16.4.82
  • ==9.20.2.21
  • ==9.22.2.32
  • ==9.20.4.34
  • ==9.16.4.85
  • ==9.18.4.40
  • ==9.22.1.3
  • ==9.20.3.20
  • ==9.18.4.82
  • ==9.22.3.191
  • ==9.16.3.19
  • ==9.16.2
  • ==9.18.4.50
  • ==9.23.1.7
  • ==9.20.4.7
  • ==9.16.4.89
  • ==9.20.3.7
  • ==9.16.4.67
  • ==9.20.4.28
  • ==9.16.3.15
  • ==9.16.3.23
  • ==9.18.4.76
  • ==9.20.4.10
  • ==9.18.4.71
  • ==9.24.1.5
  • ==9.16.4.70
  • ==9.16.4.62
  • ==9.22.2.4
  • ==9.20.3.16
  • ==9.16.4.19
  • ==9.16.4.39
  • ==9.20.1
  • ==9.22.3
  • ==9.24.1
  • ==9.18.4.66
  • ==9.16.4.9
  • ==9.24.1.155
  • ==9.16.2.7
  • ==9.16.4.48
  • ==9.20.2.22
  • ==9.16.4.38
  • ==9.24.1.11
  • ==9.16.4.27
  • ==9.23.1
  • ==9.20.3.10
  • ==9.16.4
  • ==9.16.4.76
  • ==9.18.3.39
  • ==9.16.4.84
  • ==9.18.3.46
  • ==9.18.4.52
  • ==9.16.2.14
  • ==9.23.1.3
  • ==9.18.2.8
  • ==9.16.1.28
  • ==9.16.2.3
  • ==9.18.2
  • ==9.16.2.11
  • ==9.18.4.8
  • ==9.22.1.1
  • ==9.22.3.5
  • ==9.16.4.14
  • ==9.20.4
  • ==9.20.3.13
  • ==9.18.4.22
  • ==9.18.4.34
  • ==9.20.4.14
  • ==9.20.2.10
  • ==9.18.3
  • ==9.16.4.57
  • ==9.16.3.3
  • ==9.20.3.9
  • ==9.18.3.56
  • ==9.16.1
  • ==9.18.4.135
  • ==9.20.4.235
  • ==9.20.2
  • ==9.24.10
  • ==9.16.4.42
  • ==9.18.3.53
Dismissed
(no matching packages found)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.

References

Affected products

WP Import Export Lite
  • <3.9.33
Dismissed
(no matching packages found)
Permalink CVE-2026-73166
8.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Nozomi Networks Labs identified a CWE-94: Improper Control of Generation …

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root.

Affected products

EKI-1242EIMS
  • =<1.06.01
EKI-1242IEIMS
  • =<1.06.01
Dismissed
(no matching packages found)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode

The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. This opcode is considered internal-only and the official client doesn't have API for it, but a client that can open a plain TCP session on the ZooKeeper client port (2181 by default) - with NO authentication and NO ACL permissions - can delete any empty persistent znode (including regular persistent nodes, container nodes, and TTL nodes) by issuing the raw protocol OpCode deleteContainer (20). The deleteContainer request path completely skips both the session check and the DELETE ACL check that are enforced by the regular delete (OpCode 2) path. This is an authorization bypass / ACL enforcement bug. This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.9.6 or 3.8.7, which fixes the issue.

Affected products

org.apache.zookeeper:zookeeper
  • =<3.9.5
  • =<3.8.6
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-90022
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
usb: gadget: f_midi2: fix use-after-free in string attribute show path

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock internally, but its callers dereference the opts->info.<field> pointer before calling it, outside the lock. This races with f_midi2_opts_str_store(), which frees the old string under opts->lock when the attribute is written concurrently, the show path can read a pointer that gets freed before the lock inside str_show() is even taken. Change f_midi2_opts_str_show() to take a pointer to the string field, matching the existing pattern in f_midi2_opts_str_store(), and dereference it only after the lock is held. Update all three callers (iface_name, block name, and the EP string option macro) accordingly.

Affected products

Linux
  • <7.2.5
  • =<7.2.*
  • <6.12.110
  • <6.18.51
  • <d11f3300b39e2daad2f0d9d66ddcc39a156cb594
  • =<6.12.*
  • <6.6.157
  • =<6.18.*
  • =<*
  • <f9bdf4c4f6410a1dfafafa383a0e21069372657f
  • <e89e30f0b5d3004fe5955250bd8b04f3733e32ce
  • =<6.6.*
  • <49fab5e1bdb205c36c965d0e9677bc40d282d3a2
  • <fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b
Dismissed
(no matching packages found)
Permalink CVE-2026-14916
7.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 4 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Kong API Gateway Enterprise: JWT Algorithm-Confusion

A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an unauthenticated remote attacker may be able to craft a forged JWT that is incorrectly accepted as valid, leading to authentication bypass and potential compromise of confidentiality, integrity, and availability.

Affected products

Kong Enteprise Gateway
  • <3.13.0.9
  • <3.14.0.12
  • <3.12.0.10
  • <3.4.3.29
  • <3.15.0.3
  • <3.10.0.17