Nearform

Fast-jwt

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 06.04.2026 16:59:43
  • Zuletzt bearbeitet 22.04.2026 19:05:01

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for different tokens can lead to cache collisions. This could cause tokens t...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 06.04.2026 15:54:03
  • Zuletzt bearbeitet 22.04.2026 20:17:47

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT alg...

  • EPSS 0.57%
  • Veröffentlicht 19.03.2025 15:41:19
  • Zuletzt bearbeitet 15.04.2026 00:35:42

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC 7519. The iss (issuer) claim validation within the fast-jwt library permits an array of strings...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 20.11.2023 18:15:07
  • Zuletzt bearbeitet 21.11.2024 08:31:14

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm confusion for all public key types. The 'publicKeyPemMatcher' in 'fast-jwt/src/crypto.js' does not proper...