A vulnerability has been found in JBERGER Mojo::JWT up to 1.1 and classified as critical. Affected is the function
decode of the component HMAC Signature Verification. Performing a manipulation results in incorrect comparison.
This vulnerability is identified as CVE-2026-9537. The attack can be initiated remotely. There is not any exploit available.