Skip to finding
important · Zero-click — Identity

A forged JWT can impersonate a Cloudflare service token in nimble_zta 0.1.2.

Affects

nimble_zta, an Elixir authentication library used by Phoenix and Plug server applications behind Cloudflare Zero Trust.

The library discarded JOSE’s signature-verification verdict and returned decoded claims even after verification failed.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026