HIGH
appsup-dart
CVE published 2026-03-31
CVE-2026-34240
A high-severity vulnerability was discovered in the JOSE library, which could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. This issue has been patched in version 0 [truncated]