PatchSiren

appsup-dart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH appsup-dart CVE published 2026-03-31

CVE-2026-34240

A high-severity vulnerability was discovered in the JOSE library, which could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. This issue has been patched in version 0 [truncated]