Summary
Cloud Foundry published two UAA advisories with direct Claude collaboration
credits. CVE-2026-40965 exposed EC private-key components through the public
/token_keys endpoint when deployments used EC keys for JWT signing.
CVE-2026-41005 allowed UAA to treat SAML encryption as a substitute for IdP signatures in two SAML flows, accepting unsigned encrypted assertions or responses under affected configurations.
Attribution
Both advisories credit Arthur Chan from Ada Logics in collaboration with Claude and Anthropic Research. The vulnerabilities were accepted by Cloud Foundry and fixed through UAA and CF Deployment release upgrades.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.