---
id: CVE-2026-78426
title: >-
  The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the
  same RSA signature field
summary: >-
  The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the
  same RSA signature field. An attacker holding a valid JWT that has not
  expired, but was logged out of NeuVector, can continue using the non-expired
  token with equ…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: go
product: neuvector
affected:
  - neuvector <= v5.6.1
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:07:38.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78426'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426'
    label: meissner@suse.de
  - url: >-
      https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j
    label: meissner@suse.de
tags:
  - nvd
  - cve.org
epss: 0.00116
epssPercentile: 0.01848
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:40:12.782525Z'
ingestedAt: '2026-09-17T10:15:37.170Z'
---

## Overview

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
