Package compatibility
jsonwebtoken
Node.js requirements from npm Registry (engines.node) for the jsonwebtoken package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2022-23541GHSA-hjrf-2m68-5959
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
- CVE-2022-23540GHSA-qwph-4952-7xr6
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
- CVE-2022-23539GHSA-8cf7-32gw-wr33
jsonwebtoken unrestricted key type could lead to legacy keys usage
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
- CVE-2015-9235GHSA-c7hr-j4mj-j2w6
Verification Bypass in jsonwebtoken
- Affected:
- <4.2.2
- Fixed in:
- 4.2.2
- Source:
- OSV source · Advisory
