CVE-2026-78426

CVE-2026-78426 published: The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of ...

View full NVD advisory → ← Back to CVE watch