Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nearform

First CVE: Nov 20, 2023Active for: 3 yearsTotal CVEs: 7

Nearform maintains a small but strategically positioned portfolio of open-source libraries and tools, notably the fast-jwt authentication package and the urql GraphQL client, which are embedded across many downstream applications despite the vendor's narrow direct footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through authentication and data-validation weakness classes—insufficient verification of data authenticity, input validation flaws, and cross-site scripting—that reflect the high-trust, protocol-critical role these libraries play in application security. Defenders should monitor this vendor's releases closely, as flaws in widely adopted authentication and data-handling primitives can propagate rapidly through dependent projects; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nearform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2023
2 years ago
Most Recent CVE
Apr 9, 2026
106 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34950CRITICAL
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any le
Apr 6, 20269.132NONO
CVE-2026-35039CRITICAL
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for di
Apr 6, 20269.131NONO
CVE-2026-35042HIGH
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When
Apr 6, 20267.526NONO
CVE-2026-35041MEDIUM
fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configu
Apr 9, 20266.522NONO
CVE-2023-48223MEDIUM
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm confusion for all public key types.
Nov 20, 20235.920NONO
CVE-2026-35040MEDIUM
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allo
Apr 9, 20265.319NONO
CVE-2024-24556MEDIUM
urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that
Jan 30, 20246.118NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
14%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nearform.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nearform — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nearform's Products

View all 1 CNAs →

Top CWEs