MODERATEMaven →
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
Affected packages
- dev.dsf:dsf-bpe-process-api-v2— all versions
- dev.dsf:dsf-bpe-server— all versions
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/datasharingframework/dsf/security/advisories/GHSA-xmj9-7625-f634
- https://nvd.nist.gov/vuln/detail/CVE-2026-40942
- https://github.com/datasharingframework/dsf/commit/31c2e974dfd4351756104ee8c53dbcd666192fef
- https://github.com/datasharingframework/dsf/commit/d3ca59b4daccde16a006fedeccce28fd1f826908
- https://github.com/datasharingframework/dsf
Structured record: https://osv.dev/vulnerability/GHSA-xmj9-7625-f634
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta