⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2022-21449

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

Java Psychic Signatures: Completely broken ECDSA implementation accepts any signature including a blank one in Java 15-18. Breaks JWT verification (ES256/ES384/ES512), TLS client auth, and code signing. Update JDK immediately. Audit all JWT libraries using Java crypto for ECDSA.

📋 Official Description

Faulty implementation of the Elliptic Curve Digital Signature Algorithm (ECDSA) in Java 15-18 allows attackers to forge any signature by sending a blank signature (Psychic Signatures in Java).

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →