CVE-2026-55735
Received Received - Intake

Improper Cryptographic Signature Verification in Guardian Session Revocation

Vulnerability report for CVE-2026-55735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: EEF

Description

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and payload). The resulting unverified claims are forwarded directly to the configured token module's revoke callback and the implementation's on_revoke callback, a state-mutating sink. The sibling operations refresh/2 and exchange/4 both call decode_and_verify first, so the signature is checked before anything acts on the claims; revoke/3 is the only state-mutating path that acts on claims without verifying the signature. An attacker who knows or guesses a victim's identifying claim values (jti, sub) can forge a JWT carrying those claims, sign it with an arbitrary key, and submit it to any endpoint that funnels a caller-supplied token into Guardian.revoke/3 (the standard logout / session-revocation pattern). When the token module mutates state keyed by the claims (whitelist deletion or blacklist insertion, for example a GuardianDb-style store), the victim's legitimate session is evicted. This is an unauthenticated session-revocation denial of service; the attacker never needs the signing secret. This issue affects guardian: from 1.0.0 before 2.4.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-02
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
guardian guardian From 1.0.0 (inc) to 2.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper verification of cryptographic signatures in the ueberauth guardian library. An unauthenticated attacker can forge a token to revoke a victim's session by submitting a crafted JWT to endpoints using Guardian.revoke/3. The function decodes tokens without verifying signatures, allowing attackers to manipulate session state and evict legitimate sessions.

Detection Guidance

This vulnerability cannot be detected through standard network or system commands as it involves a flaw in the Guardian library's token revocation process. The issue is specific to the improper verification of cryptographic signatures in the ueberauth guardian library.

Impact Analysis

If you use the affected guardian library versions (1.0.0 to 2.4.0), an attacker could log out users by revoking their sessions without authentication. This leads to denial of service for legitimate users, disrupting access to services relying on guardian for authentication.

Compliance Impact

This vulnerability could lead to unauthorized session revocation, potentially violating data protection requirements under GDPR (e.g., integrity of user sessions) and HIPAA (e.g., secure access controls). Unauthenticated attackers could disrupt legitimate user sessions, compromising compliance with access management and session security controls.

Mitigation Strategies

Upgrade the guardian library to version 2.4.1 or later to address the improper signature verification in the revoke/3 function. Ensure all dependencies are updated to avoid similar issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart