All 3 CVE vulnerabilities found in jans, with AI-generated Chinese analysis, references, and POCs.
Vendor: JanssenProject
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-45795 | Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server CWE-347 | 5.3 | Medium | 2026-07-16 |
| CVE-2025-54876 | Jans CLI stores plaintext passwords in the local cli_cmd.log file CWE-522 | 5.5AI | MediumAI | 2025-08-05 |
| CVE-2025-53003 | Janssen Config API returns results without scope verification CWE-200 | 4.3AI | MediumAI | 2025-07-01 |
All 3 known CVE vulnerabilities affecting jans with full Chinese analysis, references, and POCs where available.