{"id":"UBUNTU-CVE-2026-45363","details":"ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.","modified":"2026-07-15T19:46:10.438808762Z","published":"2026-07-14T22:16:00Z","upstream":["CVE-2026-45363"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-45363"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-45363"},{"type":"REPORT","url":"https://github.com/jwt/ruby-jwt/commit/9820020869ad147b941e49d96ab8beba35532964"},{"type":"REPORT","url":"https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f"},{"type":"REPORT","url":"https://github.com/jwt/ruby-jwt/releases/tag/v2.10.3"},{"type":"REPORT","url":"https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0"},{"type":"REPORT","url":"https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x"}],"affected":[{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0-3"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.0-3","binary_name":"ruby-jwt"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}},{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-jwt","binary_version":"1.5.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}},{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.6-1","2.1.0-2"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-jwt","binary_version":"2.1.0-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}},{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.2-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-jwt","binary_version":"2.2.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}},{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.0-2","2.7.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-jwt","binary_version":"2.7.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}},{"package":{"name":"ruby-jwt","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ruby-jwt?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-jwt","binary_version":"2.7.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-45363.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}