Junglewise Threat Intelligence

CVE-2025-59936: get-jwks cache poisoning in JWKS key retrieval

CVE-2025-59936 · Severity: low · CVSS 3 · Published 2025-09-26

Vendors: npm.

Executive brief

get-jwks is a Node.js library used to fetch and cache JSON Web Key Sets (JWKS) for JWT validation in applications. A cache poisoning vulnerability allows attackers to inject malicious public keys into the shared cache, then reuse those keys to forge JWTs with arbitrary claims, bypassing issuer validation even when issuer checks are implemented. This enables attackers to impersonate any issuer and gain unauthorized access to protected resources.

Technical details

The vulnerability is a cache-key collision flaw (CWE-116) in the JWKS cache mechanism. The library constructs cache keys by concatenating algorithm, key ID (kid), and domain without proper escaping: `${alg}:${kid}:${normalizedDomain}`. An attacker can craft two JWTs: the first with a malicious issuer in the domain field that, when parsed, causes a chosen public key to be fetched and cached; the second JWT uses carefully crafted kid and domain values to create the identical cache key, forcing the library to reuse the attacker's public key for signature validation of the legitimate issuer. Since issuer validation typically occurs after key retrieval in common JWT verification flows, the forged token passes both signature and issuer checks. No authentication is required; the attack is network-accessible. Patched in version 11.0.2 via proper cache-key escaping.

Affected products

  • npm get-jwks <= 11.0.1

Timeline

  • 2025-09-26: disclosed
  • 2025-09-26: patched: fixed in version 11.0.2

References