{"id":"CVE-2026-45795","summary":"Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server","details":"The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized RSA-OAEP algorithm when forceSignedRequestObject=true. This issue is fixed in version 2.0.0.","aliases":["GHSA-r3gj-4pj2-9j3j"],"modified":"2026-07-22T04:18:39.837757Z","published":"2026-07-16T16:35:58.581Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45795.json"},"references":[{"type":"WEB","url":"https://github.com/JanssenProject/jans/releases/tag/v2.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45795.json"},{"type":"ADVISORY","url":"https://github.com/JanssenProject/jans/security/advisories/GHSA-r3gj-4pj2-9j3j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45795"},{"type":"FIX","url":"https://github.com/JanssenProject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c"},{"type":"FIX","url":"https://github.com/JanssenProject/jans/pull/13438"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/janssenproject/jans","events":[{"introduced":"0"},{"fixed":"0cdd214870ee30eb2186261f21c85b9e9fc63b5c"},{"fixed":"6d2a701c7133ddd57352a78f081368df45cef24b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.16.0","nightly","v1.15.0","v1.14.0","v1.13.0","v1.11.0","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.6","v1.0.0-beta.16","docker-jans-persistence-loader-v1.0.0-beta.16","docker-jans-client-api-v1.0.0-beta.16","docker-jans-certmanager-v1.0.0-beta.16","docker-jans-fido2-v1.0.0-beta.16","docker-jans-scim-v1.0.0-beta.16","docker-jans-configurator-v1.0.0-beta.16","docker-jans-auth-server-v1.0.0-beta.16","docker-jans-config-api-v1.0.0-beta.16","docs-v1.0.0-beta.16","jans-auth-server-v1.0.0-beta.16","jans-config-api-v1.0.0-beta.16","jans-cli-v1.0.0-beta.16","jans-pycloudlib-v1.0.0-beta.16","jans-linux-setup-v1.0.0-beta.16","jans-fido2-v1.0.0-beta.16","jans-eleven-v1.0.0-beta.16","jans-bom-v1.0.0-beta.16","jans-core-v1.0.0-beta.16","jans-client-api-v1.0.0-beta.16","jans-orm-v1.0.0-beta.16","jans-scim-v1.0.0-beta.16","jans-notify-v1.0.0-beta.16","v1.0.0-beta.15","docker-jans-configurator-v1.0.0-beta.15","docker-jans-fido2-v1.0.0-beta.15","docker-jans-config-api-v1.0.0-beta.15","docker-jans-auth-server-v1.0.0-beta.15","docker-jans-certmanager-v1.0.0-beta.15","docker-jans-scim-v1.0.0-beta.15","docker-jans-client-api-v1.0.0-beta.15","docker-jans-persistence-loader-v1.0.0-beta.15","jans-pycloudlib-v1.0.0-beta.15","jans-notify-v1.0.0-beta.15","jans-orm-v1.0.0-beta.15","jans-config-api-v1.0.0-beta.15","jans-client-api-v1.0.0-beta.15","jans-core-v1.0.0-beta.15","jans-bom-v1.0.0-beta.15","jans-auth-server-v1.0.0-beta.15","jans-fido2-v1.0.0-beta.15","jans-scim-v1.0.0-beta.15","jans-linux-setup-v1.0.0-beta.15","jans-cli-v1.0.0-beta.15","docs-v1.0.0-beta.15","jans-eleven-v1.0.0-beta.15","charts-v1.0.0-beta.14","docker-jans-certmanager-v1.0.0-beta.14","docker-jans-client-api-v1.0.0-beta.14","docker-jans-scim-v1.0.0-beta.14","docker-jans-auth-server-v1.0.0-beta.14","docker-jans-config-api-v1.0.0-beta.14","docker-jans-fido2-v1.0.0-beta.14","docker-jans-persistence-loader-v1.0.0-beta.14","docker-jans-configurator-v1.0.0-beta.14","jans-pycloudlib-v1.0.0-beta.14","docker-jans-configurator-v1.0.0-beta.13","docker-jans-config-api-v1.0.0-beta.13","docker-jans-certmanager-v1.0.0-beta.13","docker-jans-client-api-v1.0.0-beta.13","docker-jans-fido2-v1.0.0-beta.13","docker-jans-auth-server-v1.0.0-beta.13","docker-jans-scim-v1.0.0-beta.13","docker-jans-persistence-loader-v1.0.0-beta.13","jans-pycloudlib-v1.0.0-beta.13","1.0.0-a4","1.0.0-a3","v1.0.0-a2","v1.0.0-a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45795.json","vanir_signatures_modified":"2026-07-22T04:18:39Z","vanir_signatures":[{"digest":{"function_hash":"44031514290720186135170064299041461435","length":4832},"id":"CVE-2026-45795-4b67c680","signature_type":"Function","signature_version":"v1","source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"file":"jans-auth-server/server/src/main/java/io/jans/as/server/authorize/ws/rs/AuthzRequestService.java","function":"processRequestObject"},"deprecated":false},{"source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"function":"JwtAuthorizationRequest","file":"jans-auth-server/server/src/main/java/io/jans/as/server/model/authorize/JwtAuthorizationRequest.java"},"deprecated":false,"digest":{"function_hash":"55295134861953190977950534608338234770","length":2602},"id":"CVE-2026-45795-562f67a6","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"file":"jans-auth-server/server/src/main/java/io/jans/as/server/model/authorize/JwtAuthorizationRequest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["333512052850681878559681176541338945954","141964319923136204474306550593026865427","157997046405146035689210404504167881979","277901644627296947139688009383863221870","207293046935486244563266884812248697919","80323134280162963699505089705652428356","48634178701393570669951547077276769870","254337684541584605557508605648454846825","179422240701729594439141291815654361878","282365195962059770488021826045690448121","256540472080996393864474540439487366349","179782188240092741166873508795214642696","227226594625453002865774897315195178053","18369026044762067432375980099273133536","274838302651472997088669148086757717523","2251991042862173607202774574011661389","40102165585049001623955486641540574228","78947059173585515876341617421988375691","315978223232896559514460222025175020736","149776969212239351651770921904496495205","182429047803309202887971141380952685783","7243568864596898124929710657319575934","157318775348752886976863712073937290889","81704977018086475282746295211333416226","41656299950168860291547970187674890966","240757030173200971745191751152473461749","38329715579005210650742772220852937051","140599430851597422754123788074749909882","123626579282784660396308145780474529535","257643695515457410339685907197637482094","149220611147395397622349908683556175837","108587633537507210242609878158511307392"]},"id":"CVE-2026-45795-93b149bd"},{"digest":{"line_hashes":["177791189405646581738156022654768277760","233681568145605759745915041402996139430","121976436547803875573199109821059886916","141092316314799561195961052902943401176","182392426110995255216342390686168046763","251007035260650082684485914545899475362","210112195790600805384344269860968792916","96940245384669777194844003391720433217"],"threshold":0.9},"id":"CVE-2026-45795-9dd90258","signature_type":"Line","signature_version":"v1","source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"file":"jans-auth-server/server/src/test/java/io/jans/as/server/model/authorize/JwtAuthorizationRequestTest.java"},"deprecated":false},{"id":"CVE-2026-45795-bdc4ee2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"file":"jans-auth-server/server/src/test/java/io/jans/as/server/authorize/ws/rs/AuthzRequestServiceTest.java"},"deprecated":false,"digest":{"line_hashes":["151357872774124039117045744592704661080","127553580044011008432602504279233452860","267416021832192919458924041910547056081","207184132062378812291035141974289482621","295509053807689551398219642437036577901","6041332625366706375431278310650874319","14672378391151266235446042298182572314","238256986005047605815375524335378067404","322265663847547179884462351754464324842","245239366656365810536078855138225827123","32997191675433891766512365915456813230","26268785038124489638154536763604207511","118828716470184370529693107071522870360","252906269787052539084200405249404701120","336993132420522890914024072046536164748","141525403308637081568773079288205565476","72045079638537752075991055089569899882","231741196318919842371247836424742919151","39977155417161006485008988356021830855","46371796272417399878938152403074171942","142088578179265087349365927305844065524","17371201460967007018708858715485621729","201391145618075966673323026516404230930","211696146336466570027547661900319640274","36266474770259604092309554881291210836"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c","target":{"file":"jans-auth-server/server/src/main/java/io/jans/as/server/authorize/ws/rs/AuthzRequestService.java"},"deprecated":false,"digest":{"line_hashes":["228466561948157721686582038646273802013","74861373958976920432498413893311581229","34128420049082539079335157453509043367","285224173619963366720586103928850394457","118312878125989329475426465742053473981"],"threshold":0.9},"id":"CVE-2026-45795-be603104","signature_type":"Line"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}