Skip to content
Red HatCVE-2026-84185

Red Hat Ansible Automation Platform 2: improper signature check

Medium5.9CVE-2026-84185 · Published Sep 3, 2026 · updated Sep 8, 2026

A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Ansible Automation Platform 2
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux 7: null pointer dereference
High7.5Sep 3
Red Hat gfs2-utils: out-of-bounds read
Medium5.3Sep 3
Red Hat gfs2-utils. The metadata walk code: denial of service
Medium4.7Sep 3
Red Hat gfs2-utils. The hash table traversal code: denial of service
Medium4.7Sep 3
Red Hat gfs2-utils.: out-of-bounds write
High7.0Sep 3
Red Hat gfs2-utils.: out-of-bounds write
High7.0Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.