{"id":"CVE-2026-78426","title":"The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field","summary":"The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-863"],"vendor":"go","product":"neuvector","affected":["neuvector <= v5.6.1"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:07:38.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78426","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426","label":"meissner@suse.de"},{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j","label":"meissner@suse.de"}],"tags":["nvd","cve.org"],"epss":0.00116,"epssPercentile":0.01848,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T12:40:12.782525Z"},"ingestedAt":"2026-09-17T10:15:37.170Z","slug":"CVE-2026-78426","body":"## Overview\n\nThe NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}