logo

Critical Cloud Foundry Key Disclosure Bug Exposes JWT Signing Keys

ID: 429faf47-558d-511c-9cb4-ea7384f2513a

STIX ID: report--429faf47-558d-511c-9cb4-ea7384f2513a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

Critical vulnerability CVE-2026-40965 in Cloud Foundry UAA causes the public /token_keys endpoint to leak Elliptic Curve private keys, allowing unauthenticated attackers to forge valid JWTs; affected UAA builds v76.12.0 through v78.12.0 should be upgraded to v78.13.0 or later (and global templates to v56.1.0+) immediately to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.