Showing 1 vulnerability on this page for node-jws

Signals CISA KEV Ransomware Nuclei
auth0 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

auth0/node-jws improper HMAC signature verification vulnerability

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verif

CWE-347Dec 4, 2025
CVSS7.5v3.1EPSS0.219%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX