Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. n8n
  4. ›
  5. CVE-2026-65599

CVE-2026-65599: n8n: Google Service Account Private Key Exposed in JWT Header

July 22, 2026

When n8n was configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header’s kid field (which should only have held a key identifier). Since JWT headers were Base64-encoded rather than encrypted, the key could be recovered by anything that logged or inspected the JWT.

An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use.

Only instances using Google Service Account credentials are affected.

References

  • github.com/advisories/GHSA-9r8p-h6cc-6qhm
  • github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
  • github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
  • github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
  • github.com/n8n-io/n8n/security/advisories/GHSA-9r8p-h6cc-6qhm
  • nvd.nist.gov/vuln/detail/CVE-2026-65599
  • www.vulncheck.com/advisories/n8n-before-credential-exposure-via-jwt-header

Code Behaviors & Features

Detect and mitigate CVE-2026-65599 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.123.64, all versions starting from 2.0.0-rc.0 before 2.29.8, all versions starting from 2.30.0 before 2.30.1

Fixed versions

  • 1.123.64
  • 2.29.8
  • 2.30.1

Solution

Upgrade to versions 1.123.64, 2.29.8, 2.30.1 or above.

Impact 8.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-312: Cleartext Storage of Sensitive Information

Source file

npm/n8n/CVE-2026-65599.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:44 +0000.