Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAuth0 Wcf Service Jwt
APPAuth0< 1.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-7947CRITICAL9.8PL ✓same vendor
CSV injection w pluginie Login by Auth0 dla WordPress (przed 4.0.0)
CVE-2015-9235CRITICAL9.8PL ✓same vendor
Pominięcie weryfikacji podpisu JWT w module jsonwebtoken (algorithm confusion)
CVE-2018-6873CRITICAL9.8PL ✓same vendor
Auth0 auth0.js — brak walidacji audience w JWT umożliwia privilege escalation
CVE-2026-42280HIGH7.1same vendor
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, t...
CVE-2026-34236HIGH8.2same vendor
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19...