PoC Archive PoC Archive

tag

Jwe

Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230 web Patched
CVE-2026-49230webCRITICAL 9.1Patched2026-07-27pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
CVE-2026-29000 web Patched
CVE-2026-29000webCRITICAL 9.8Patched2026-07-05