You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This CVE record has been marked for NVD enrichment efforts.
Description
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key configurations, only deployments using EC keys for JWT signing.
Affected versions:
- uaa_release: v76.12.0 through v78.12.0 (inclusive); fixed in v78.13.0 or later
- CF Deployment: v30.0.0 through v56.0.0 (inclusive); fixed in v56.1.0 or later (bundles uaa_release v78.13.0)
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Cloud Foundry Foundation, Description: Las versiones de Cloud Foundry UAA v76.12.0 hasta v78.12.0 son vulnerables a una exposición de clave privada. El servidor contiene una vulnerabilidad donde las claves privadas EC (Curva Elíptica) se exponen inadvertidamente a través del endpoint público /token_keys. Este endpoint está diseñado para proporcionar material de clave pública para la verificación de tokens JWT, pero expone incorrectamente componentes de clave privada para claves EC. La vulnerabilidad afecta a los despliegues que utilizan claves EC para la firma de tokens JWT. La vulnerabilidad no afecta las configuraciones de clave RSA, solo los despliegues que utilizan claves EC para la firma de tokens JWT.
Versiones afectadas:
- uaa_release: v76.12.0 hasta v78.12.0 (inclusive); corregido en v78.13.0 o posterior
- CF Deployment: v30.0.0 hasta v56.0.0 (inclusive); corregido en v56.1.0 o posterior (incluye uaa_release v78.13.0)
Title: Cloud Foundry Foundation, Description: Las versiones de Cloud Foundry UAA v76.12.0 hasta v78.12.0 son vulnerables a una exposición de clave privada. El servidor contiene una vulnerabilidad donde las claves privadas EC (Curva Elíptica) se exponen inadvertidamente a través del endpoint público /token_keys. Este endpoint está diseñado para proporcionar material de clave pública para la verificación de tokens JWT, pero expone incorrectamente componentes de clave privada para claves EC. La vulnerabilidad afecta a los despliegues que utilizan claves EC para la firma de tokens JWT. La vulnerabilidad no afecta las configuraciones de clave RSA, solo los despliegues que utilizan claves EC para la firma de tokens JWT.
Versiones afectadas:
- uaa_release: v76.12.0 hasta v78.12.0 (inclusive); corregido en v78.13.0 o posterior
- CF Deployment: v30.0.0 hasta v56.0.0 (inclusive); corregido en v56.1.0 o posterior (incluye uaa_release v78.13.0)
CVE Translated by NIST7/22/2026 1:10:00 PM
Action
Type
Old Value
New Value
Added
Translation
Title: Cloud Foundry Foundation, Description: Las versiones de Cloud Foundry UAA v76.12.0 hasta v78.12.0 son vulnerables a una exposición de clave privada. El servidor contiene una vulnerabilidad donde las claves privadas EC (Curva Elíptica) se exponen inadvertidamente a través del endpoint público /token_keys. Este endpoint está diseñado para proporcionar material de clave pública para la verificación de tokens JWT, pero expone incorrectamente componentes de clave privada para claves EC. La vulnerabilidad afecta a los despliegues que utilizan claves EC para la firma de tokens JWT. La vulnerabilidad no afecta las configuraciones de clave RSA, solo los despliegues que utilizan claves EC para la firma de tokens JWT.
Versiones afectadas:
- uaa_release: v76.12.0 hasta v78.12.0 (inclusive); corregido en v78.13.0 o posterior
- CF Deployment: v30.0.0 hasta v56.0.0 (inclusive); corregido en v56.1.0 o posterior (incluye uaa_release v78.13.0)
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key configurations, only deployments using EC keys for JWT signing.
Affected versions:
- uaa_release: v76.12.0 through v78.12.0 (inclusive); fixed in v78.13.0 or later
- CF Deployment: v30.0.0 through v56.0.0 (inclusive); fixed in v56.1.0 or later (bundles uaa_release v78.13.0)