<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 22:02:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322192</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322192</link>
      <description>EUVD-2026-322192</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322192</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41164</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41164</link>
      <description>&lt;p&gt;nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an active: true introspection response. This vulnerability is fixed in 6.2.3 and 5.4.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an active: true introspection response. This vulnerability is fixed in 6.2.3 and 5.4.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41164</guid>
    </item>
    <item>
      <title>GHSA-9hmg-827w-9rhj — nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hmg-827w-9rhj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nuts-foundation/nuts-node&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The v1 access token introspection endpoint (`/auth/v1/introspect_access_token`) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an `active: true` introspection response.&lt;/p&gt;
&lt;p&gt;## Background&lt;/p&gt;
&lt;p&gt;In the v1 auth flow ([Nuts RFC003](https://nuts-foundation.gitbook.io/v1/rfc/rfc003-oauth2-authorization)), access tokens are JWTs signed by the authorizer&amp;#39;s key with:
- `iss` = authorizer organization DID
- `sub` = requester organization DID
- `service` = purpose of use (e.g. `&amp;#34;eOverdracht&amp;#34;`)
- `typ` header = `&amp;#34;JWT&amp;#34;` (default, not explicitly set)&lt;/p&gt;
&lt;p&gt;Verifiable Presentations are also JWTs with `typ: &amp;#34;JWT&amp;#34;` (per W3C VC Data Model 1.1). The W3C VC Data Model 2.0 changed this to `vp+jwt` specifically to prevent this class of confusion attack (See [Securing Verifiable Credentials using JOSE and COSE 3.1.1](https://www.w3.org/TR/vc-jose-cose/#securing-with-jose)).&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;The introspection endpoint performs only standard JWT checks. It does not perform the following Nuts-specific access token checks:&lt;/p&gt;
&lt;p&gt;1. **Validate the `typ` header**: both ATs and VPs use `&amp;#34;JWT&amp;#34;`
2. **Bind `iss` to the signing key**: it doesn&amp;#39;t verify that the `iss` claim matches the DID extracted from the `kid`
3. **Validate required claims**: `service` can be empty; `vp` claim is silently ignored by `FromMap()` which uses lenient…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nuts-foundation/nuts-node&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The v1 access token introspection endpoint (`/auth/v1/introspect_access_token`) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an `active: true` introspection response.&lt;/p&gt;
&lt;p&gt;## Background&lt;/p&gt;
&lt;p&gt;In the v1 auth flow ([Nuts RFC003](https://nuts-foundation.gitbook.io/v1/rfc/rfc003-oauth2-authorization)), access tokens are JWTs signed by the authorizer&amp;#39;s key with:
- `iss` = authorizer organization DID
- `sub` = requester organization DID
- `service` = purpose of use (e.g. `&amp;#34;eOverdracht&amp;#34;`)
- `typ` header = `&amp;#34;JWT&amp;#34;` (default, not explicitly set)&lt;/p&gt;
&lt;p&gt;Verifiable Presentations are also JWTs with `typ: &amp;#34;JWT&amp;#34;` (per W3C VC Data Model 1.1). The W3C VC Data Model 2.0 changed this to `vp+jwt` specifically to prevent this class of confusion attack (See [Securing Verifiable Credentials using JOSE and COSE 3.1.1](https://www.w3.org/TR/vc-jose-cose/#securing-with-jose)).&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;The introspection endpoint performs only standard JWT checks. It does not perform the following Nuts-specific access token checks:&lt;/p&gt;
&lt;p&gt;1. **Validate the `typ` header**: both ATs and VPs use `&amp;#34;JWT&amp;#34;`
2. **Bind `iss` to the signing key**: it doesn&amp;#39;t verify that the `iss` claim matches the DID extracted from the `kid`
3. **Validate required claims**: `service` can be empty; `vp` claim is silently ignored by `FromMap()` which uses lenient…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hmg-827w-9rhj</guid>
    </item>
  </channel>
</rss>
