---
id: CVE-2026-81829
title: >-
  A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by
  applications to verify JSON Web Tokens signed by AWS Application Load
  Balancers
summary: >-
  A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by
  applications to verify JSON Web Tokens signed by AWS Application Load
  Balancers. When the AWS_ALB key provider is configured, the resolver
  constructs the key-fetch UR…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: Red Hat
product: exploit-intelligence/agent-client-rhel9
affected:
  - exploit-intelligence/agent-client-rhel9 (all versions)
  - quarkus-smallrye-jwt (all versions)
  - smallrye-jwt
  - quarkus-smallrye-jwt (all versions)
  - smallrye-jwt (all versions)
  - smallrye-jwt (all versions)
  - smallrye-jwt (all versions)
published: '2026-09-17'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:11.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81829'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-81829'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2524980'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81829.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-81829'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81829'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00584
epssPercentile: 0.45601
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T15:45:20.084526Z'
ingestedAt: '2026-09-17T14:19:30.980Z'
---

## Overview

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack · no fix planned: Red Hat build of Apicurio Registry 3, Exploit Intelligence, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81829.json)
