{"id":"CVE-2026-81829","published":"2026-09-17T14:17:32.323","lastModified":"2026-09-21T18:17:11.057","description":"A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69470","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-81829","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524980","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}