CVE-2026-34240 is a high-severity vulnerability (CVSS 7.5) affecting the JOSE library, versions prior to 0.3.5+1, allowing unauthenticated, remote attackers to forge valid JWS/JWT tokens. This occurs because the library incorrectly treats header-provided keys (jwk) as trusted verification candidates, leading to a high integrity impact through a low-complexity network attack. While there is no evidence of active exploitation or public exploit code, the vulnerability has received some community discussion. Organizations should update to version 0.3.5+1 or implement the workaround to reject tokens where the header jwk does not match a trusted key.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.5\+1CPE matchmatch criteria | cpe:2.3:a:appsup-dart:jose:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.