CVE-2026-65599: n8n: Google Service Account Private Key Exposed in JWT Header
When n8n was configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header’s kid field (which should only have held a key identifier). Since JWT headers were Base64-encoded rather than encrypted, the key could be recovered by anything that logged or inspected the JWT.
An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use.
Only instances using Google Service Account credentials are affected.
References
- github.com/advisories/GHSA-9r8p-h6cc-6qhm
- github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
- github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- github.com/n8n-io/n8n/security/advisories/GHSA-9r8p-h6cc-6qhm
- nvd.nist.gov/vuln/detail/CVE-2026-65599
- www.vulncheck.com/advisories/n8n-before-credential-exposure-via-jwt-header
Code Behaviors & Features
Detect and mitigate CVE-2026-65599 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →