CVE-2022-23540(auth0 / jsonwebtoken)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the `jwt.verify()` function. This issue has been fixed, please update to version 9.0.0 which removes the default support for the none algorithm in the `jwt.verify()` method. There will be no impact, if you update to version 9.0.0 and you don’t need to allow for the `none` algorithm. If you need 'none' algorithm, you have to explicitly specify that in `jwt.verify()` options.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsonwebtoken

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
jsonwebtoken

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Full discourse1 post
  • Harsh Sanket@HarshSanket1

    CVE-2022-23540 in jsonwebtoken could allow signature validation bypass when jwt.verify() was used without defining allowed algorithms. CVE-2023-48223 affected fast-jwt with JWT algorithm confusion do not let an incoming token choose verification behavior.

    1001015
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appauth0jsonwebtoken-node.js-

Explore more