Antonio Attanasio
3 exploits
Active since Apr 2026
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
CVSS 5.3
ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification
CVSS 4.2
fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
CVSS 9.1