What is CVE-2026-65599?
A credential exposure vulnerability exists in older n8n versions where the full PEM private key from a Google Service Account is mistakenly placed in the JWT header's kid field. Since JWT headers are only Base64-encoded, attackers can easily decode them and steal the sensitive key. Update immediately to the patched versions: 1.123.64, 2.29.8, or 2.30.1.
Azərbaycanca: n8n proqramının köhnə versiyaları Google xidmət hesabı məlumatlarını sızdıran kritik boşluq aşkarlanıb. Özəl PEM açarı JWT başlığına səhvən yerləşdirildiyindən, zərərli şəxslər Base64 kodlaşdırmasını açaraq bu həssas məlumatı əldə edə bilər. Təsirə məruz qalmamaq üçün dərhal göstərilən patched versiyalara yeniləyin.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Google
FAQ1
Which n8n versions are affected by CVE-2026-65599 and how to remediate?
The vulnerability affects older n8n versions. Since the full PEM private key from a Google Service Account is mistakenly placed in the JWT header's kid field, attackers can decode the Base64-encoded header to steal the sensitive key. Immediately update to the patched versions: 1.123.64, 2.29.8, or 2.30.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.