Jose Node Cjs Runtime Project maintains a specialized cryptographic and key-management library for Node.js environments, serving a focused but security-sensitive role in JWT and token-handling workflows. The observed vulnerability footprint is modest and centered on this single library component; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jose Node Cjs Runtime Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29446MEDIUM jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS38 | Apr 16, 2021 | 5.9 | 22 | NO | NO |
CVE-2021-29445MEDIUM jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS38 | Apr 16, 2021 | 5.9 | 21 | NO | NO |
CVE-2021-29444MEDIUM jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384 | Apr 16, 2021 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jose Node Cjs Runtime Project.
Media articles that mention a CVE ID that affects a product developed by Jose Node Cjs Runtime Project — matched by CVE ID, not by vendor name.