CVE-2026-81829

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.

  • Published Sep 17, 2026
  • CVSS 5.3 medium
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-81829 at the National Vulnerability Database