Package compatibility
jsonwebtoken 7
What Node.js versions does this jsonwebtoken version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=0.12
- Tip version
- 7.4.3
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other jsonwebtoken lines
Security
Advisories affecting jsonwebtoken 7 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 3
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2022-23541GHSA-hjrf-2m68-5959
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
- CVE-2022-23540GHSA-qwph-4952-7xr6
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
- CVE-2022-23539GHSA-8cf7-32gw-wr33
jsonwebtoken unrestricted key type could lead to legacy keys usage
- Affected:
- <9.0.0
- Fixed in:
- 9.0.0
- Source:
- OSV source · Advisory
