Xmidt maintains a narrowly scoped cryptographic library (CJWT) for JWT claim validation in embedded and IoT contexts, representing a focused security component rather than a broad product platform. The durable signal in its disclosure history centers on control-flow correctness in cryptographic validation logic, a weakness class that demands rigorous attention in authentication-critical code. Current CVE counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xmidt over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19324HIGH Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance. | Mar 20, 2020 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xmidt.
Media articles that mention a CVE ID that affects a product developed by Xmidt — matched by CVE ID, not by vendor name.