CVE-2026-33996: LibJWT has NULL/bounds validation in JWK octet and RSA PSS parsing

Published Mar 27, 2026
·
Updated

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the jwk2key tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

Affected Software

2 affected components
libjwt LibJWT>=3.0.0<3.3.0
libjwt LibJWT>=3.0.0<3.3.0

Event History

Mar 27, 2026
CVE Published
via MITRE·10:21 PM
Data Sourced
via MITRE·10:21 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33996?

CVE-2026-33996 is classified as a high-severity vulnerability due to its potential to allow exploitation via NULL and bounds validation issues.

2

How do I fix CVE-2026-33996?

To fix CVE-2026-33996, upgrade LibJWT to version 3.3.0 or later to ensure proper handling of NULL values in JSON Web Key parsing.

3

What versions of LibJWT are affected by CVE-2026-33996?

LibJWT versions between 3.0.0 and 3.3.0 are affected by CVE-2026-33996.

4

What specific functionality is impacted by CVE-2026-33996 in LibJWT?

CVE-2026-33996 impacts the JWK (JSON Web Key) parsing functionality for RSA-PSS, leading to vulnerabilities when handling malformed input.

5

Is there a workaround for CVE-2026-33996 if immediate upgrade is not possible?

There is no documented workaround for CVE-2026-33996, and upgrading to the patched version is strongly recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203