Lcobucci develops a JWT (JSON Web Token) library focused on cryptographic signing and verification for authentication workflows. The vendor's vulnerability signal centers on insufficient verification of data authenticity, a structural concern in token-handling implementations where validation gaps can undermine the security properties of signed credentials. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lcobucci over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-based algorithms (HS256, HS384, and HS512) combined wi | Sep 28, 2021 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lcobucci.
Media articles that mention a CVE ID that affects a product developed by Lcobucci — matched by CVE ID, not by vendor name.