jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
History

Sun, 17 Aug 2025 04:15:00 +0000

Type Values Removed Values Added
Description jwt v5.4.3 was discovered to contain weak encryption. jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

Fri, 15 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Jwt Project
Jwt Project jwt
CPEs cpe:2.3:a:jwt_project:jwt:*:*:*:*:*:*:*:*
Vendors & Products Jwt Project
Jwt Project jwt

Thu, 31 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-326
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
Description jwt v5.4.3 was discovered to contain weak encryption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-31T00:00:00.000Z

Updated: 2025-08-17T04:00:19.045Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45770

cve-icon Vulnrichment

Updated: 2025-07-31T20:05:55.126Z

cve-icon NVD

Status : Modified

Published: 2025-07-31T20:15:33.280

Modified: 2025-08-17T04:15:40.680

Link: CVE-2025-45770

cve-icon Redhat

No data.