CVE-2026-41164

Source
https://cve.org/CVERecord?id=CVE-2026-41164
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41164.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41164
Aliases
Downstream
Related
Published
2026-05-26T17:35:59.019Z
Modified
2026-07-31T18:29:54.234470506Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
nuts-node: JWT type confusion in v1 access token introspection allows VP replay as access token
Details

nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspectaccesstoken) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a Verifiable Presentation (VP) JWT to be replayed as an access token and receive an active: true introspection response. This vulnerability is fixed in 6.2.3 and 5.4.31.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41164.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-345"
    ]
}
References

Affected packages

Git / github.com/nuts-foundation/nuts-node

Affected ranges

Type
GIT
Repo
https://github.com/nuts-foundation/nuts-node
Events
Introduced
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "6.0.0-alpha.1"
        },
        {
            "fixed": "6.2.3"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "5.4.31"
        }
    ]
}

Affected versions

nuts-node-chart-0.*
nuts-node-chart-0.0.1
nuts-node-chart-0.0.2
nuts-node-chart-0.0.3
nuts-node-chart-0.0.4
nuts-node-chart-0.0.5
nuts-node-chart-0.0.6
nuts-node-chart-0.0.7
Other
publish-binaries
tmp_publish-binaries2
tmp_publish-binaries3
v1.*
v1.0.0
v2.*
v2.0.0
v3.*
v3.0.0
v4.*
v4.0.0
v4.1.0
v5.*
v5.0.0
v5.1.0
v5.1.0-rc.1
v5.1.0-rc.2
v5.1.0-rc.3
v5.2.0-rc.1
v5.3.0-alpha.1
v5.3.0-alpha.2
v5.3.0-rc.1
v5.4.0
v5.4.0-rc.1
v5.4.0-rc.2
v5.4.1
v5.4.10
v5.4.11
v5.4.12
v5.4.13
v5.4.14
v5.4.15
v5.4.16
v5.4.17
v5.4.18
v5.4.19
v5.4.2
v5.4.20
v5.4.21
v5.4.22
v5.4.23
v5.4.24
v5.4.25
v5.4.26
v5.4.27
v5.4.28
v5.4.29
v5.4.3
v5.4.30
v5.4.4
v5.4.5
v5.4.6
v5.4.7
v5.4.8
v5.4.9
v6.*
v6.0.0
v6.0.0-alpha.1
v6.0.0-alpha.2
v6.0.0-alpha.3
v6.0.0-alpha.4
v6.0.0-alpha.5
v6.0.0-alpha.6
v6.0.0-alpha.7
v6.0.0-beta.1
v6.0.0-beta.10
v6.0.0-beta.11
v6.0.0-beta.12
v6.0.0-beta.13
v6.0.0-beta.2
v6.0.0-beta.3
v6.0.0-beta.4
v6.0.0-beta.8
v6.0.0-beta.9
v6.0.0-rc.1
v6.0.0-rc.10
v6.0.0-rc.2
v6.0.0-rc.3
v6.0.0-rc.4
v6.0.0-rc.5
v6.0.0-rc.6
v6.0.0-rc.7
v6.0.0-rc.8
v6.0.0-rc.9
v6.1.0
v6.1.0-alpha.2
v6.1.0-beta.2
v6.1.0-beta.3
v6.1.0-rc.1
v6.1.0-rc.2
v6.1.0-rc.3
v6.1.9
v6.2.0
v6.2.1
v6.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41164.json"