Nearform maintains a small but strategically positioned portfolio of open-source libraries and tools, notably the fast-jwt authentication package and the urql GraphQL client, which are embedded across many downstream applications despite the vendor's narrow direct footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through authentication and data-validation weakness classes—insufficient verification of data authenticity, input validation flaws, and cross-site scripting—that reflect the high-trust, protocol-critical role these libraries play in application security. Defenders should monitor this vendor's releases closely, as flaws in widely adopted authentication and data-handling primitives can propagate rapidly through dependent projects; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nearform over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34950CRITICAL fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any le | Apr 6, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-35039CRITICAL fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for di | Apr 6, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-35042HIGH fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When | Apr 6, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-35041MEDIUM fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configu | Apr 9, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-48223MEDIUM fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm confusion for all public key types. | Nov 20, 2023 | 5.9 | 20 | NO | NO |
CVE-2026-35040MEDIUM fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allo | Apr 9, 2026 | 5.3 | 19 | NO | NO |
CVE-2024-24556MEDIUM urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that | Jan 30, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nearform.
Media articles that mention a CVE ID that affects a product developed by Nearform — matched by CVE ID, not by vendor name.