๐Ÿ” CVE Alert

CVE-2026-33996

UNKNOWN 0.0

LibJWT has NULL/bounds validation in JWK octet and RSA PSS parsing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
6th

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

CWE CWE-476
Vendor benmcollins
Product libjwt
Published Mar 27, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for benmcollins libjwt

Be the first to know when new unknown vulnerabilities affecting benmcollins libjwt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

benmcollins / libjwt
>= 3.0.0, < 3.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/benmcollins/libjwt/security/advisories/GHSA-ph96-hqpc-9f66 github.com: https://github.com/benmcollins/libjwt/commit/cfd890286fa49ae61b534c937c9f0428b5c6034c