CVE-2026-45795: Janssenproject Jans

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized RSA-OAEP algorithm when forceSignedRequestObject=true. This issue is fixed in version 2.0.0.

Affected products

Published 2026-07-16. Last modified 2026-07-16.