Intel

AIKIDO-2026-176390

nimble_zta is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureCVE-2026-91187 Published Yesterday

92

Critical Risk

This Affects:

ELIXIRnimble_zta
0.1.2 - 0.1.2
Fixed in 0.1.3
Are you affected? Scan for Free

TL;DR

The nimble_zta Cloudflare authentication strategy accepts Zero Trust JWTs without checking whether JOSE.JWT.verify/2 reports the signature as valid. A crafted service token with the expected issuer and required claims is authenticated even when its cryptographic signature fails verification. Applications that enable the Cloudflare strategy can be impersonated by any party able to submit such a token. The fix checks the verification boolean before authenticating the JWT.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the Cloudflare authentication strategy.

Background info

nimble_zta is vulnerable to Improper Verification of Cryptographic Signature in versions 0.1.2 - 0.1.2.

How to fix this

Upgrade the nimble_zta library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform