๐Ÿ” CVE Alert

CVE-2026-78426

LOW 3.7

Logout bypass via alternate JWT spelling

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.

CWE CWE-863
Vendor go
Product neuvector
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for go neuvector

Be the first to know when new low vulnerabilities affecting go neuvector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

go / neuvector
0 โ‰ค v5.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/neuvector/neuvector/security/advisories/GHSA-wcx5-mq6c-c54j bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-78426