CVE-2016-10555 affects jwt-simple versions 0.3.0 and earlier, stemming from a lack of algorithm enforcement in the jwt.decode() function. This allows an attacker to specify the algorithm, potentially tricking the server into using an RSA public key as an HMAC private key, leading to arbitrary data forgery. Rated as MEDIUM severity (CVSS 6.5), it is network-exploitable with low attack complexity and high integrity impact. While it has a high EPSS score and FAUCET Risk Score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.0CPE matchmatch criteria | cpe:2.3:a:jwt-simple_project:jwt-simple:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.