Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: jaeger: * jaeger-2.19.0-1.2.hum1 (aarch64, x86_64) * jaeger-2.19.0-1.2.hum1.src (src) Security Fix(es): jaeger: * CVE-2026-49852
AI Analysis
Technical Summary
The joserfc Python library, which implements JSON Object Signing and Encryption (JOSE) standards, has an improper authentication vulnerability (CWE-287) in versions before 1.6.8. Specifically, the jwt.decode function accepts forged HMAC-signed tokens if the caller supplies an empty string or None as the verification key. This occurs because the HMACAlgorithm.sign and verify methods pass the output of OctKey.get_op_key(...) to hmac.new(...) without rejecting zero-length keys. OctKey.import_key only emits a SecurityWarning for keys shorter than 14 bytes but does not reject zero-length keys, allowing token forgery. The issue is resolved in joserfc version 1.6.8.
Potential Impact
An attacker can forge HMAC-signed JSON Web Tokens (JWTs) that the library will accept as valid if the verification key is empty or None. This can lead to bypassing authentication controls relying on token verification, potentially allowing unauthorized access or privilege escalation in applications using vulnerable versions of joserfc.
Mitigation Recommendations
Upgrade to joserfc version 1.6.8 or later, where this vulnerability is fixed by rejecting zero-length keys during HMAC verification. No other mitigations are indicated by the vendor advisory.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: jaeger: * jaeger-2.19.0-1.2.hum1 (aarch64, x86_64) * jaeger-2.19.0-1.2.hum1.src (src) Security Fix(es): jaeger: * CVE-2026-49852
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The joserfc Python library, which implements JSON Object Signing and Encryption (JOSE) standards, has an improper authentication vulnerability (CWE-287) in versions before 1.6.8. Specifically, the jwt.decode function accepts forged HMAC-signed tokens if the caller supplies an empty string or None as the verification key. This occurs because the HMACAlgorithm.sign and verify methods pass the output of OctKey.get_op_key(...) to hmac.new(...) without rejecting zero-length keys. OctKey.import_key only emits a SecurityWarning for keys shorter than 14 bytes but does not reject zero-length keys, allowing token forgery. The issue is resolved in joserfc version 1.6.8.
Potential Impact
An attacker can forge HMAC-signed JSON Web Tokens (JWTs) that the library will accept as valid if the verification key is empty or None. This can lead to bypassing authentication controls relying on token verification, potentially allowing unauthorized access or privilege escalation in applications using vulnerable versions of joserfc.
Mitigation Recommendations
Upgrade to joserfc version 1.6.8 or later, where this vulnerability is fixed by rejecting zero-length keys during HMAC verification. No other mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gg9x-qcx2-xmrh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-49852"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a46ecbb27e9c7971943cddf
Added to database: 07/02/2026, 22:56:59 UTC
Last enriched: 07/25/2026, 21:00:14 UTC
Last updated: 09/03/2026, 22:19:22 UTC
Views: 139
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.