Executive brief
A vulnerability in the ruby-jwt library, which is used to handle secure digital tokens for authentication and data exchange, allows attackers to bypass security checks. By providing a specially crafted token and an empty or missing security key, an attacker can trick the system into accepting forged credentials. This could lead to unauthorized access to sensitive user data or administrative functions in applications using this library.
Technical details
The ruby-jwt library is vulnerable to an authentication bypass when verifying tokens using HMAC-based algorithms (HS256, HS384, HS512). The root cause is that the library's `JWT.decode` method and `verify_signature!` function do not enforce a non-empty key precondition. Because `OpenSSL::HMAC.digest` returns a valid, predictable digest when provided with an empty string key, an attacker can forge a token that matches this empty-key signature. This path is also triggered if a provided `key_finder` returns `nil` or an empty string for an unknown key. The vulnerability allows remote, unauthenticated attackers to bypass signature verification and gain unauthorized access. The issue is resolved in versions 2.10.3 and 3.2.0.
Affected products
- jwt ruby-jwt < 2.10.3, >= 3.0.0 < 3.2.0
Timeline
- 2026-05-13: patched: Initial fix in version 3.2.0
- 2026-05-22: patched: Backported fix in version 2.10.3
- 2026-07-14: disclosed: CVE published
References
- https://github.com/jwt/ruby-jwt/commit/9820020869ad147b941e49d96ab8beba35532964
- https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
- https://github.com/jwt/ruby-jwt/releases/tag/v2.10.3
- https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0
- https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x