The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized RSA-OAEP algorithm when forceSignedRequestObject=true. This issue is fixed in version 2.0.0.
{
"cwe_ids": [
"CWE-347"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45795.json"
}"2026-08-12T16:41:35Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45795.json"
[
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 4832.0,
"function_hash": "44031514290720186135170064299041461435"
},
"id": "CVE-2026-45795-4b67c680",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"function": "processRequestObject",
"file": "jans-auth-server/server/src/main/java/io/jans/as/server/authorize/ws/rs/AuthzRequestService.java"
}
},
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2602.0,
"function_hash": "55295134861953190977950534608338234770"
},
"id": "CVE-2026-45795-562f67a6",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"function": "JwtAuthorizationRequest",
"file": "jans-auth-server/server/src/main/java/io/jans/as/server/model/authorize/JwtAuthorizationRequest.java"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"333512052850681878559681176541338945954",
"141964319923136204474306550593026865427",
"157997046405146035689210404504167881979",
"277901644627296947139688009383863221870",
"207293046935486244563266884812248697919",
"80323134280162963699505089705652428356",
"48634178701393570669951547077276769870",
"254337684541584605557508605648454846825",
"179422240701729594439141291815654361878",
"282365195962059770488021826045690448121",
"256540472080996393864474540439487366349",
"179782188240092741166873508795214642696",
"227226594625453002865774897315195178053",
"18369026044762067432375980099273133536",
"274838302651472997088669148086757717523",
"2251991042862173607202774574011661389",
"40102165585049001623955486641540574228",
"78947059173585515876341617421988375691",
"315978223232896559514460222025175020736",
"149776969212239351651770921904496495205",
"182429047803309202887971141380952685783",
"7243568864596898124929710657319575934",
"157318775348752886976863712073937290889",
"81704977018086475282746295211333416226",
"41656299950168860291547970187674890966",
"240757030173200971745191751152473461749",
"38329715579005210650742772220852937051",
"140599430851597422754123788074749909882",
"123626579282784660396308145780474529535",
"257643695515457410339685907197637482094",
"149220611147395397622349908683556175837",
"108587633537507210242609878158511307392"
],
"threshold": 0.9
},
"id": "CVE-2026-45795-93b149bd",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"file": "jans-auth-server/server/src/main/java/io/jans/as/server/model/authorize/JwtAuthorizationRequest.java"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"177791189405646581738156022654768277760",
"233681568145605759745915041402996139430",
"121976436547803875573199109821059886916",
"141092316314799561195961052902943401176",
"182392426110995255216342390686168046763",
"251007035260650082684485914545899475362",
"210112195790600805384344269860968792916",
"96940245384669777194844003391720433217"
],
"threshold": 0.9
},
"id": "CVE-2026-45795-9dd90258",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"file": "jans-auth-server/server/src/test/java/io/jans/as/server/model/authorize/JwtAuthorizationRequestTest.java"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"151357872774124039117045744592704661080",
"127553580044011008432602504279233452860",
"267416021832192919458924041910547056081",
"207184132062378812291035141974289482621",
"295509053807689551398219642437036577901",
"6041332625366706375431278310650874319",
"14672378391151266235446042298182572314",
"238256986005047605815375524335378067404",
"322265663847547179884462351754464324842",
"245239366656365810536078855138225827123",
"32997191675433891766512365915456813230",
"26268785038124489638154536763604207511",
"118828716470184370529693107071522870360",
"252906269787052539084200405249404701120",
"336993132420522890914024072046536164748",
"141525403308637081568773079288205565476",
"72045079638537752075991055089569899882",
"231741196318919842371247836424742919151",
"39977155417161006485008988356021830855",
"46371796272417399878938152403074171942",
"142088578179265087349365927305844065524",
"17371201460967007018708858715485621729",
"201391145618075966673323026516404230930",
"211696146336466570027547661900319640274",
"36266474770259604092309554881291210836"
],
"threshold": 0.9
},
"id": "CVE-2026-45795-bdc4ee2f",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"file": "jans-auth-server/server/src/test/java/io/jans/as/server/authorize/ws/rs/AuthzRequestServiceTest.java"
}
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"228466561948157721686582038646273802013",
"74861373958976920432498413893311581229",
"34128420049082539079335157453509043367",
"285224173619963366720586103928850394457",
"118312878125989329475426465742053473981"
],
"threshold": 0.9
},
"id": "CVE-2026-45795-be603104",
"source": "https://github.com/janssenproject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
"target": {
"file": "jans-auth-server/server/src/main/java/io/jans/as/server/authorize/ws/rs/AuthzRequestService.java"
}
}
]