CVE-2015-9235

EPSS 37.5%

Verification Bypass in jsonwebtoken

Published: 10/9/2018Modified: 2/4/2026

Description

Versions 4.2.1 and earlier of `jsonwebtoken` are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm. ## Recommendation Update to version 4.2.2 or later.

Affected packages (1)

References (6)