Medium severity5.3NVD Advisory· Published Nov 2, 2020· Updated Jun 17, 2026
CVE-2020-28042
CVE-2020-28042
Description
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ServiceStackNuGet | < 5.9.2 | 5.9.2 |
Affected products
3- ServiceStack/ServiceStackdescription
Patches
Vulnerability mechanics
References
10- github.com/ServiceStack/ServiceStack/commit/540d4060e877a03ae95343c1a8560a26768585eenvdPatchThird Party AdvisoryWEB
- www.shielder.it/advisories/servicestack-jwt-signature-verification-bypass/nvdExploitThird Party Advisory
- www.shielder.it/blog/2020/11/re-discovering-a-jwt-authentication-bypass-in-servicestack/nvdExploitThird Party Advisory
- forums.servicestack.net/t/servicestack-v5-9-2-released/8850nvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-v5rv-hpxg-8x49ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28042ghsaADVISORY
- snyk.io/vuln/SNYK-DOTNET-SERVICESTACK-1035519ghsaWEB
- www.nuget.org/packages/ServiceStackghsaWEB
- www.shielder.it/advisories/servicestack-jwt-signature-verification-bypassghsaWEB
- www.shielder.it/blog/2020/11/re-discovering-a-jwt-authentication-bypass-in-servicestackghsaWEB
News mentions
0No linked articles in our index yet.