Jwt Simple Project maintains a narrowly scoped JWT (JSON Web Token) authentication library, a small component that sits deep in application authentication stacks but attracts limited direct scrutiny. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jwt Simple Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10555MEDIUM Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting | May 31, 2018 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jwt Simple Project.
Media articles that mention a CVE ID that affects a product developed by Jwt Simple Project — matched by CVE ID, not by vendor name.