{"id":"CVE-2026-81829","title":"A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers","summary":"A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-22"],"vendor":"Red Hat","product":"exploit-intelligence/agent-client-rhel9","affected":["exploit-intelligence/agent-client-rhel9 (all versions)","quarkus-smallrye-jwt (all versions)","smallrye-jwt","quarkus-smallrye-jwt (all versions)","smallrye-jwt (all versions)","smallrye-jwt (all versions)","smallrye-jwt (all versions)"],"published":"2026-09-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T18:17:11.057","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81829","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69470","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81829","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524980","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81829.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81829"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81829"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00387,"epssPercentile":0.32517,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-17T15:45:20.084526Z"},"ingestedAt":"2026-09-17T14:19:30.980Z","slug":"CVE-2026-81829","body":"## Overview\n\nA flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apicurio Registry 3, Red Hat build of Quarkus, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack · no fix planned: Red Hat build of Apicurio Registry 3, Exploit Intelligence, Red Hat build of Quarkus, Red Hat JBoss Enterprise Application Platform 8, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81829.json)","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}