CVE-2026-40965 is a critical information disclosure vulnerability in Cloud Foundry UAA affecting uaa_release versions v76.12.0 through v78.12.0 and CF Deployment versions v30.0.0 through v56.0.0. In affected deployments, the publicly accessible /token_keys endpoint, which is intended to publish public key material for JWT verification, incorrectly serializes Elliptic Curve signing keys and exposes private key components, including the EC private parameter. The flaw is specific to deployments that use EC keys for JWT token signing; RSA signing configurations are not affected. Reported root-cause details indicate the vulnerable code path serialized a full JWK for EC keys rather than a public-only JWK, causing disclosure of secret signing material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical information disclosure vulnerability in Cloud Foundry UAA that exposed elliptic-curve private key components via the public /token_keys endpoint when EC keys were used for JWT signing.
A critical unauthenticated key disclosure vulnerability in Cloud Foundry's User Account and Authentication (UAA) component that exposes Elliptic Curve private keys via the public/token_keys endpoint, enabling token forgery.
A private key exposure vulnerability in Cloud Foundry UAA where EC private keys can be disclosed via the public /token_keys endpoint, affecting deployments that use EC keys for JWT signing.
An unauthenticated sensitive information disclosure vulnerability in Cloud Foundry UAA where the /token_keys endpoint exposes EC private key material, allowing attackers to forge JWTs and compromise the platform trust model.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.