CVE Disclosure

CVE-2026-45363

jwt/ruby-jwt · Ruby

Empty-key HMAC bypass

CVSS7.4
SeverityHigh
StatusNVD: RESERVED

Summary

CVE-2026-45363 is a high-severity vulnerability affecting jwt/ruby-jwt (Ruby): Empty-key HMAC bypass.

References

Disclosure

Reported by Kai Aizen. Status: NVD: RESERVED. Coordinated through standard NVD/MITRE/GHSA channels.

disclosure contextall 30 cves →
Author
Kai Aizen
Independent offensive security researcher. 30 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.