Vulnerability Description
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426
- https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j
FAQ
What is CVE-2026-78426?
CVE-2026-78426 is a vulnerability with a CVSS score of 3.7 (LOW). The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue...
How severe is CVE-2026-78426?
CVE-2026-78426 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-78426?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.