{"id":"GHSA-5pq9-5mpr-jj85","summary":"Jervis Has a JWT Algorithm Confusion Vulnerability","details":"### Vulnerability\n\nhttps://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L244-L249\n\nThe code doesn't validate that the JWT header specifies `\"alg\":\"RS256\"`.\n\n### Impact\n\nDepending on the broader system, this could allow JWT forgery.\n\nInternally this severity is low since JWT is only intended to interface with GitHub.  External users should consider severity moderate.\n\n### Patches\n\nJervis patch will explicitly verify the algorithm in the header matches expectations and further verify the JWT structure.\n\nUpgrade to Jervis 2.2.\n\n### Workarounds\n\nExternal users should consider using an alternate JWT library or upgrade.\n\n### References\n\n- [RFC 7518: JSON Web Algorithms](https://datatracker.ietf.org/doc/html/rfc7518)","aliases":["CVE-2025-68925"],"modified":"2026-02-03T03:11:37.438351Z","published":"2026-01-13T14:56:04Z","database_specific":{"github_reviewed_at":"2026-01-13T14:56:04Z","nvd_published_at":"2026-01-13T20:16:07Z","cwe_ids":["CWE-347"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/samrocketman/jervis/security/advisories/GHSA-5pq9-5mpr-jj85"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68925"},{"type":"WEB","url":"https://github.com/samrocketman/jervis/commit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a"},{"type":"PACKAGE","url":"https://github.com/samrocketman/jervis"},{"type":"WEB","url":"https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L244-L249"},{"type":"WEB","url":"http://github.com/samrocketman/jervis/commit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a"}],"affected":[{"package":{"name":"net.gleske:jervis","ecosystem":"Maven","purl":"pkg:maven/net.gleske/jervis"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2"}]}],"versions":["0.1","0.10","0.11","0.12","0.13","0.2","0.3","0.4","0.5","0.5.1","0.5.2","0.6","0.7","0.8","0.9","1.0","1.1","1.2","1.3","1.4","1.5","1.6","1.7","2.0","2.0.1","2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-5pq9-5mpr-jj85/GHSA-5pq9-5mpr-jj85.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}