Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place. | |
| Title | Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver | |
| First Time appeared |
Redhat
Redhat apicurio Registry Redhat exploit Intelligence Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat quarkus |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:apicurio_registry:3 cpe:/a:redhat:exploit_intelligence:0 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:quarkus:3 |
|
| Vendors & Products |
Redhat
Redhat apicurio Registry Redhat exploit Intelligence Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat quarkus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-17T15:45:29.941Z
Reserved: 2026-08-27T13:55:30.358Z
Link: CVE-2026-81829
Updated: 2026-09-17T15:45:23.956Z
Status : Received
Published: 2026-09-17T14:17:32.323
Modified: 2026-09-17T16:17:47.080
Link: CVE-2026-81829
No data.
OpenCVE Enrichment
No data.