Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fast Jwt MEDIUM 6.5
CVE-2026-35041

fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud…

Fix: 6.2.1+
Fix from $1,600 2026-04-09
Fast Jwt MEDIUM 5.3
CVE-2026-35040

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, …

Fix: 6.2.1+
Fix from $1,600 2026-04-09
Fast Jwt CRITICAL 9.1
CVE-2026-35039

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not pro…

Fix: 6.1.0+
Fix from $2,300 2026-04-06
Fast Jwt HIGH 7.5
CVE-2026-35042

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter def…

Fix: 6.2.0+
Fix from $1,950 2026-04-06
Fast Jwt CRITICAL 9.1
CVE-2026-34950

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ an…

Fix: 6.2.0+
Fix from $2,300 2026-04-06
Urql MEDIUM 6.1
CVE-2024-24556

urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an att…

Fix: 1.1.1+
Fix from $1,600 2024-01-30
Fast Jwt MEDIUM 5.9
CVE-2023-48223

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm conf…

Fix: 3.3.2+
Fix from $1,600 2023-11-20