Vulnerabilities
Vulnerable Software
Jwt Project:  >> Jwt  >> 1.0.1  Security Vulnerabilities
jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
CVSS Score
7.0
EPSS Score
0.0
Published
2025-07-31
The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signatures via a timing attack.
CVSS Score
7.5
EPSS Score
0.001
Published
2017-01-23


Contact Us

Shodan ® - All rights reserved