Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
782540
AlmaLinux
5354
Alpaquita
11918
Alpine
4290
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
581
Bitnami
8406
Chainguard
9476
CleanStart
1889
CRAN
14
crates.io
2575
Debian
60524
Echo
6872
GHC
3
GIT
95053
GitHub Actions
54
Go
8328
Hackage
32
Hex
191
Julia
1103
Linux
25861
Mageia
6057
Maven
6712
MinimOS
92445
npm
222847
NuGet
1789
opam
19
openEuler
7315
openSUSE
13567
OSS-Fuzz
3963
Packagist
6721
Pub
11
PyPI
23904
Red Hat
21339
Rocky Linux
3710
Root
17642
RubyGems
4570
SUSE
21633
SwiftURL
58
TuxCare
5651
Ubuntu
58039
VSCode
20
Wolfi
6585
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-10132
npm/react-jsonwebtoken
Malicious code in react-jsonwebtoken (npm)
10 Jul
No fix available
MAL-2024-11216
npm/jsonwebtoken-js
Malicious code in jsonwebtoken-js (npm)
05 Dec 2024
No fix available
MAL-2024-11133
npm/crypto-jsonwebtoken
Malicious code in crypto-jsonwebtoken (npm)
29 Nov 2024
No fix available
GHSA-hjrf-2m68-5959
npm/jsonwebtoken
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
22 Dec 2022
Fix available
Severity - 5.0 (Medium)
GHSA-qwph-4952-7xr6
npm/jsonwebtoken
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
22 Dec 2022
Fix available
Severity - 6.4 (Medium)
GHSA-8cf7-32gw-wr33
npm/jsonwebtoken
jsonwebtoken unrestricted key type could lead to legacy keys usage
22 Dec 2022
Fix available
Severity - 8.1 (High)
GHSA-c7hr-j4mj-j2w6
npm/jsonwebtoken
Verification Bypass in jsonwebtoken
09 Oct 2018
Fix available
npm - OSV