The Jwt Project maintains a niche cryptographic library focused on JSON Web Token implementation, a foundational component for authentication and data integrity across distributed systems. Its vulnerability exposure centers on the core JWT product and clusters around inadequate encryption strength, reflecting the cryptographic demands and evolution of token-based authentication standards. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jwt Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-45770HIGH jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library | Jul 31, 2025 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jwt Project.
Media articles that mention a CVE ID that affects a product developed by Jwt Project — matched by CVE ID, not by vendor name.