Description
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated same-origin SSRF allowing disclosure of internal data
Action: Apply Patch
AI Analysis

Impact

A flaw in the SmallRye JWT AwsAlbKeyResolver allows an unauthenticated attacker to send a crafted JWT with a malicious kid header. The resolver concatenates this header directly into the key-fetch URL without sanitizing path traversal or query separators, enabling forced GET requests to arbitrary paths within the same origin as the key endpoint. This remote request can read non-public endpoints or internal data before the JWT signature is validated, potentially exposing sensitive information.

Affected Systems

The vulnerability impacts Red Hat builds that incorporate SmallRye JWT, including Red Hat Build of Quarkus, Red Hat Build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform 8, and the Red Hat JBoss Enterprise Application Platform Expansion Pack. Specific affected versions were not listed in the available data, so any release that uses the described AwsAlbKeyResolver without the fix could be vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote unauthenticated request that exploits the unsanitized JWT header. Since the flaw allows reading internal resources before authentication, the potential impact ranges from data exposure to facilitating further lateral movement within an organization. Without an official mitigation, the risk remains until the library is updated or the insecure key provider is disabled.

Generated by OpenCVE AI on September 17, 2026 at 22:03 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Upgrade Red Hat Build of Quarkus or related products to a version that contains the SmallRye JWT fix.
  • Disable or tightly restrict the AWS_ALB key provider to prevent unsanitized kid values from influencing key-fetch URLs.
  • Apply network segmentation or firewall rules to block same-origin GET requests from the application server to internal or non-public endpoints on the key‑endpoint origin.

Generated by OpenCVE AI on September 17, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3
Vendors & Products Redhat quarkus
References

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Apicurio Registry
Redhat build Of Quarkus
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat smallrye Health
Vendors & Products Redhat build Of Apicurio Registry
Redhat build Of Quarkus
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat smallrye Health

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.
Title Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver
First Time appeared Redhat
Redhat apicurio Registry
Redhat exploit Intelligence
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat quarkus
Weaknesses CWE-22
CPEs cpe:/a:redhat:apicurio_registry:3
cpe:/a:redhat:exploit_intelligence:0
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:quarkus:3
Vendors & Products Redhat
Redhat apicurio Registry
Redhat exploit Intelligence
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat quarkus
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Apicurio Registry Build Of Apicurio Registry Build Of Quarkus Exploit Intelligence Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Smallrye Health
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T17:24:19.253Z

Reserved: 2026-08-27T13:55:30.358Z

Link: CVE-2026-81829

cve-icon Vulnrichment

Updated: 2026-09-17T15:45:23.956Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T14:17:32.323

Modified: 2026-09-21T18:17:11.057

Link: CVE-2026-81829

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T13:10:22Z

Links: CVE-2026-81829 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')