Critical Cloud Foundry Key Disclosure Bug Exposes JWT Signing Keys
ID: 429faf47-558d-511c-9cb4-ea7384f2513a
STIX ID: report--429faf47-558d-511c-9cb4-ea7384f2513a
Feed Name: securityonline.info
Threat Score
Critical vulnerability CVE-2026-40965 in Cloud Foundry UAA causes the public /token_keys endpoint to leak Elliptic Curve private keys, allowing unauthenticated attackers to forge valid JWTs; affected UAA builds v76.12.0 through v78.12.0 should be upgraded to v78.13.0 or later (and global templates to v56.1.0+) immediately to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
