VendorsAuth0jsonwebtokenall versions
Vulnerabilities

Auth0 jsonwebtoken

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2015-9235
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
Published 2018-05-29 · Modified
9.8EPSS 0.087
CVE-2022-23539
jsonwebtoken unrestricted key type could lead to legacy keys usage
Published 2022-12-22 · Modified
8.1EPSS 0.005
CVE-2022-23540
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Published 2022-12-22 · Modified
7.6EPSS 0.005
CVE-2022-23541
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Published 2022-12-22 · Modified
6.3EPSS 0.008