The Json Jwt Project maintains a specialized library for JSON Web Token (JWT) handling, a cryptographic and claims-encoding component that sits within the authentication and authorization stacks of many applications and services. Treat this as a compact vendor profile centered on a narrow but foundational product; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Json Jwt Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18848HIGH The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. | Nov 12, 2019 | 7.5 | 25 | NO | NO |
CVE-2023-51774HIGH The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass | Feb 29, 2024 | 8.4 | 23 | NO | NO |
CVE-2018-1000539MEDIUM Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that | Jun 26, 2018 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Json Jwt Project.
Media articles that mention a CVE ID that affects a product developed by Json Jwt Project — matched by CVE ID, not by vendor name.