The issue has been addressed by making the parameter configurable through the boolean Helm value krakend.config.disableJwkSecurity and setting its default value to false, ensuring that TLS certificate verification is enabled by default.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse Foundation
Eclipse Foundation eclipse Aerios |
|
| Vendors & Products |
Eclipse Foundation
Eclipse Foundation eclipse Aerios |
Thu, 03 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hard‑coded KrakenD Configuration Disables JWK TLS Verification Allowing Token Forgery |
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS certificate verification when KrakenD retrieves the JSON Web Key Set (JWKS) used to validate bearer tokens, potentially allowing an attacker with the ability to intercept this communication to provide a malicious JWKS and compromise token validation. The issue has been addressed by making the parameter configurable through the boolean Helm value krakend.config.disableJwkSecurity and setting its default value to false, ensuring that TLS certificate verification is enabled by default. | |
| Weaknesses | CWE-295 CWE-347 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2026-09-02T15:58:12.572Z
Reserved: 2026-08-31T12:32:38.204Z
Link: CVE-2026-82955
Updated: 2026-09-02T15:51:08.880Z
Status : Deferred
Published: 2026-09-02T15:17:44.860
Modified: 2026-09-03T16:41:09.297
Link: CVE-2026-82955
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:34:36Z