Known Vulnerabilities for Jsonwebtoken by Auth0
Listed below are 5 of the newest known vulnerabilities associated with "Jsonwebtoken" by "Auth0".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-31946 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 1... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2022-23541 | jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so t... | 6.3 - MEDIUM | 2022-12-22 | 2023-11-07 |
| CVE-2022-23540 | In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to sign... | 7.6 - HIGH | 2022-12-22 | 2023-11-07 |
| CVE-2022-23539 | Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature... | 8.1 - HIGH | 2022-12-23 | 2023-11-07 |
| CVE-2022-23529 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none. | Not Provided | 2022-12-21 | 2023-11-07 |
| CVE-2015-9235 | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed ... | 9.8 - CRITICAL | 2018-05-29 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Auth0 | Jsonwebtoken | 8.5.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.5.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.4.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.3.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.2.2 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.2.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.2.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.1.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.1.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.0.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 8.0.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.4.3 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.4.2 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.4.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.4.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.3.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.2.1 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.2.0 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.1.9 | All | All | All |
| Application | Auth0 | Jsonwebtoken | 7.1.8 | All | All | All |