Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-97055 Multiple Vendors

SigNoz v0.8.0 a v0.142.x: Secreto JWT vacío permite falsificación de tokens de sesión

Vulnerabilidad · Publicado 24/09/2026

8.1
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

SigNoz anterior a la versión 0.143.0 configura por defecto una clave HMAC vacía para firmar tokens JWT, permitiendo que un atacante forge tokens de sesión sin autenticación válida. Afecta a despliegues que no definen explícitamente SIGNOZ_TOKENIZER_JWT_SECRET o SIGNOZ_JWT_SECRET. La validación de configuración no rechaza valores vacíos, comprometiendo la integridad de sesiones en plataformas de observabilidad y monitoreo.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user — including an administrator — by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque.

Puntuación CVSS

Score: 8.1/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Debilidades (CWE)

CWE-1188

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Actualizar inmediatamente a SigNoz v0.143.0 o superior
  • Verificar en logs de despliegue si SIGNOZ_TOKENIZER_JWT_SECRET está vacío o indefinido
  • Forzar la definición de secreto fuerte en variables de entorno antes de reiniciar servicios
  • Revocar tokens JWT emitidos antes de la actualización
  • Auditar accesos a SigNoz en el período vulnerable
Esta alerta fue generada automáticamente a partir del NVD del NIST.