-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4787-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
September 18, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : ruby-jwt
Version : 2.5.0-1+deb12u1
CVE ID : CVE-2026-45363
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token
standard. JWT.decode(token, '', true, algorithm: 'HS256') accepts an
attacker-forged token because OpenSSL::HMAC.digest('SHA256', '',
payload) returns a valid digest under an empty key and no empty-key
precondition exists in the HMAC algorithm. The same path is reached
when a keyfinder block or key_finder: argument returns an empty
string, nil, or an array containing nil for an unknown key, affecting
HS256, HS384, and HS512 verification through JWT.decode and
JWT::EncodedToken#verify_signature!
For Debian 12 bookworm, this problem has been fixed in version
2.5.0-1+deb12u1.
We recommend that you upgrade your ruby-jwt packages.
For the detailed security status of ruby-jwt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ruby-jwt
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmquFN4ACgkQhj1N8u2c
KO8TnA/9FPbblrjBnQ2Ms/p2m9AUeE6V25IY/OuuFC5o4fvhR5FiDKR8zAXphMWB
mLNITqRdTDnJiDR69KSvdT2g4FnYAeCTCvJy4EDJoxu0ttt475O4Ib2xolFy7rqd
wCOLuj9Ix23d0LyKRqW2wTm3qoMWj5cPRczIXYW/a86mo1yN4hyODVP67LEf/O7i
mjzSW+RM/NJzwhUOhBzFtxe/O1aWASXA7mjfNr/0zEvDmuKJEwr6DlDouoZYMq5I
5OncQkHc5aELsdiR3oy66qA4ggrwm8+ovxdbnGPMk2PuHJUjdYpHJBqCNEiVhTmt
Ir69M63AxpjTlN7iP0xUA7ON8zZQSjWC5p1/UbNHbnJ+0QzrnSrD6KFPuDZDqdt2
54RXpQSHDqFWpN81Xk9FBGHrnLGPKtC956bLU+89WsKZRYDdR0EStKlbg9epd+xn
HlpteuRRDwjbhEDZbkDLY6u+mzHGEW7AgjRameo6yvc1f0wIgubFtp2rOsMusiW7
KYy7ewovY22qh2z55APniLDYDcMUNTlul6EHZ8ftMFfiIhUw/XVGwLciA4htJ3F7
RS4nop7kOwhf0ex16TW0Voz9rdxC00/uf0Zwdr84jfn5qBex+5afwy4zl4JfXJlr
pbtUX4VpXwqUD5wTDzA8mXoVgxLLxyUVRwz+LDfF4pCGa7UveQk=
=CJeA
-----END PGP SIGNATURE-----