Keats maintains the jsonwebtoken library, a focused cryptographic component widely used for JWT generation and validation across web applications and APIs. The observed vulnerability exposure centers on type-confusion conditions in token-processing logic, a class of flaw that can undermine authentication and authorization mechanisms reliant on this library. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keats over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25537HIGH jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, specifically, in its claim validation logic. When a standard cl | Feb 4, 2026 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keats.
Media articles that mention a CVE ID that affects a product developed by Keats — matched by CVE ID, not by vendor name.