HIGH8.1npm
GHSA-8cf7-32gw-wr33· CVE-2022-23539jsonwebtoken unrestricted key type could lead to legacy keys usage
Modified: 6/24/2024
package
pkg:npm/jsonwebtoken
jsonwebtoken unrestricted key type could lead to legacy keys usage
Modified: 6/24/2024
Verification Bypass in jsonwebtoken
Modified: 9/10/2026
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Modified: 6/24/2024
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Modified: 2/13/2025