CVE-2018-0114General(cisco / node-jose)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs). This standard specifies that a JSON Web Key (JWK) representing a public key can be embedded within the header of a JWS. This public key is then trusted for verification. An attacker could exploit this by forging valid JWS objects by removing the original signature, adding a new public key to the header, and then signing the object using the (attacker-owned) private key associated with the public key embedded in that JWS header.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node-jose

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
node-jose

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-14: 1Technical Details · 2026-05-14: 105-14
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • vulnX@vuln_X
    General

    7/8 — kid / jku abuse If the output token has a different kid than the input, dig in. Issuers that resolve signing keys from kid/jku/x5u headers may fetch attacker-controlled JWKS. End state: you sign your own admin tokens. CVE-2018-0114 class bugs still ship in 2026.

    Post summary

    The post highlights that JWT issuers accepting kid/jku/x5u headers can fetch attacker‑controlled JWKS, allowing forged admin tokens, and notes that CVE‑2018‑0114 class bugs continue to appear in 2026.

    11000262
    7.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcisconode-jose---

Explore more