Impact
A JWT signature verification flaw in Kong API Gateway Enterprise allows an attacker to craft a token that bypasses algorithm checks, leading to unauthorized access and potential loss of confidentiality, integrity, and availability.
Affected Systems
Kong API Gateway Enterprise components that perform JWT validation for MCP OAuth2 or DataKit integrations are affected. The fault lies in how the signing algorithm is verified against the verification key, and are not specified in the advisory.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at the present time. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated remote attacker can target services that accept JWTs, and if the attacker discovers the mismatch between the declared algorithm and the key type, they can forge a token that is incorrectly accepted, breaching authentication. The attack vector is inferred to be remote over any network interface that processes JWTs.
OpenCVE Enrichment