Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-65945

28
FAUCET Score

CVE-2025-65945 describes an improper signature verification vulnerability in auth0/node-jws versions 3.2.2 and earlier, and 4.0.0, specifically when using the HS256 algorithm. This flaw allows attackers to bypass signature verification if applications use jws.createVerify() with HMAC algorithms and incorporate user-provided data from the JWS header or payload into HMAC secret lookup routines. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and can lead to high integrity impact, though it does not affect confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.3CPE matchmatch criteria
cpe:2.3:a:auth0:node-jws:*:*:*:*:*:node.js:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:auth0:node-jws:4.0.0:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 1st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

npmpatch availablevia ghsa
Product: jwsFixed in: 3.2.3
npmpatch availablevia ghsa
Product: jwsFixed in: 4.0.1
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.8Fixed in: rhdh/rhdh-hub-rhel9:sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/code-rhel9:sha256:aa1d96a9c1d9dbf2fe077748807de1e047a17a942a87688c269aa60537b5c6d4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/openvsx-rhel9:sha256:ffe5740d684ac4a1b6c440bb4d2ca3ec20d71c008e65fa73f5143c43a7bda339
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.1Fixed in: quay/quay-rhel8:sha256:5cf58b1f54219b67c725f4a5066d9e757e7b5ece39d5de1a474a8be6a3490401
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.12Fixed in: quay/quay-rhel8:sha256:117876c6c6a12beb25983da60c8c1628f350a1797888b9f03c44b9dd737844fa
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.15Fixed in: quay/quay-rhel8:sha256:a8daa359ab7a0bc9722b25fb87aa6fd253506632640bfe7f31c9c92868421ecb
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.16Fixed in: quay/quay-rhel9:sha256:96588daff01f27db2ee335dcd957e9dec7f38a2c573e2968d9bc5835edc2957b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.9Fixed in: quay/quay-rhel8:sha256:8bd901f9d03817e599a73b4f4355236320bec1b803bd9507383277f27fde4319
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/updatetree-rhel9:sha256:cfba6d424b5e45362bb4e61d9b05bb49a24beb56a3c5ddc3aebdd2e0647179de
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/trillian-database-rhel9:sha256:50bc20bb57e8ee31e56637cafccfed2658982d81ca9bf1e71db9de4b82a2be36
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/trillian-logserver-rhel9:sha256:b246d096ad6d2b19decfa3d87bca9ab2b78000aee28b717c0a33d1202a1b2d6b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/trillian-logsigner-rhel9:sha256:d0f8b68e55173b010fd381e374f232a40fba6d03282cfd870bd9c12c492e4aec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/trillian-redis-rhel9:sha256:d97e6688aabf25ed1da6a8bf2012efb1772beed49b91456288418f6023a38dac
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.2Fixed in: rhtas/createtree-rhel9:sha256:7a1e465f93e0560194b7d5d27b46453a0dd4ebb4072235da1ffbe4ccff91d452
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.7Fixed in: rhdh/rhdh-hub-rhel9:sha256:29ada5e84c6b204cf518191a21bbd22de5cb53a61bc1812b1072ce5c28a235b2
View patch
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: io.apicurio-apicurio-registry
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/disk-image-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/mcg-core-rhel9
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console-rhel9

Vendor Advisories (2)

redhatCVE-2025-65945Important

node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm

Dec 4, 2025
npmGHSA-869p-cjfg-cm3xhigh

auth0/node-jws Improperly Verifies HMAC Signature

Dec 4, 2025

References

github.com / auth0/node-jws/commit/34c45b2c04434f925b638de6a061de9339c0ea2e
Patch
github.com / auth0/node-jws/security/advisories/GHSA-869p-cjfg-cm3x
Vendor Advisory