CVE-2026-25537Patch(keats / jsonwebtoken)

LOWCVSS 7.5 · HIGH

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Patch keats jsonwebtoken systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, specifically, in its claim validation logic. When a standard claim (such as nbf or exp) is provided with an incorrect JSON type (Like a String instead of a Number), the library’s internal parsing mechanism marks the claim as “FailedToParse”. Crucially, the validation logic treats this “FailedToParse” state identically to “NotPresent”. This means that if a check is enabled (like: validate_nbf = true), but the claim is not explicitly marked as required in required_spec_claims, the library will skip the validation check entirely for the malformed claim, treating it as if it were not there. This allows attackers to bypass critical time-based security restrictions (like “Not Before” checks) and commit potential authentication and authorization bypasses. This issue has been patched in version 10.3.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsonwebtoken

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked at 7 mentions on most recent observed day (2026-02-10)
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
jsonwebtoken

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-02-04: 1Mentions · 2026-02-10: 7Patch / Workaround · 2026-02-10: 6Technical Details · 2026-02-04: 1Technical Details · 2026-02-10: 402-0402-10
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-02-107
Disclosure1Patch6
Full discourse8 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 Urgent Security Update for Fedora Users! 🚨 Critical vulnerabilities CVE-2026-25537 & CVE-2026-25727 affect tbtools and multiple Rust applications in #Fedora 43. Read more: 👉 https://tinyurl.com/yyantywz #Security https://t.co/pFiZNCNmK1

    Post summary

    The tweet alerts Fedora 43 users to two critical CVEs affecting tbtools and various Rust applications, directing them to an external link for more information.

    0001053
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just analyzed the #Fedora 43 security advisory FEDORA-2026-f400579a21 addressing CVE-2026-25537 and related Rust crate vulnerabilities. Read more: 👉 https://tinyurl.com/2mv7z8nd #Security https://t.co/HEJy7bAFec

    Post summary

    The tweet announces a Fedora 43 security advisory that addresses CVE-2026-25537 and related Rust crate vulnerabilities, linking to the advisory for patch details and mitigation steps.

    0001041
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 Urgent #Fedora Security Update Alert! 🔒 Fedora 43 users: A critical #security advisory (FEDORA-2026-f400579a21) addresses multiple vulnerabilities including CVE-2026-25537—an authentication bypass in the jsonwebtoken Rust crate. Read more: 👉 https://tinyurl.com/5dny8wmv https://t.co/9nDuWCeKMz

    Post summary

    Fedora 43 users are warned of an authentication bypass CVE-2026-25537 in the jsonwebtoken Rust crate, and a critical advisory with a patch is available.

    0001048
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Critical security update for #Python developers using uv on #Fedora! A new patch addresses a severe JWT vulnerability (CVE-2026-25537) and multiple DoS flaws. Read more: 👉 https://tinyurl.com/yf94y45t #Security https://t.co/Zsk5hn8vtv

    Post summary

    A critical patch has been released for the uv tool on Fedora to fix a severe JWT vulnerability (CVE-2026-25537) and related DoS flaws.

    0001068
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25537 jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, specifically, in its claim validation logic. When… https://www.cve.org/CVERecord?id=CVE-2026-25537

    Post summary

    CVE‑2026‑25537 discloses a type confusion flaw in the Rust jsonwebtoken library’s claim validation logic, affecting versions prior to 10.3.0.

    00010125
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 CRITICAL: #Fedora 43 #Security Advisory Update 🚨 CVE-2026-25537 (auth bypass) + CVE-2026-25727 (stack exhaustion) now patched. Affects tuigreet, rustup, keylime-agent-rust + 6 other packages. This is a SOFTWARE SUPPLY CHAIN incident. Read more: 👉 https://tinyurl.com/4ky4w8mt https://t.co/lhce38Lp3n

    Post summary

    Fedora 43’s security advisory announces that CVE-2026-25537 (auth bypass) and CVE-2026-25727 (stack exhaustion) have been patched, with no exploit or PoC details provided.

    0000043
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ URGENT for SysAdmins & #DevOps Teams 🛡️ A critical security vulnerability (CVE-2026-25537) has been patched in the #Fedora 43 Linux kernel. Read more: 👉 https://tinyurl.com/4ezyvy77 #Security https://t.co/7djlTG3Oku

    Post summary

    Fedora 43 Linux kernel has been patched for CVE-2026-25537; administrators are urged to update to address the critical vulnerability.

    0000044
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Fedora43 security update: rust-wiremix advisory patches CVE-2026-25537 (JWT auth bypass) & DoS in time crate. Impacts auth systems & app stability. Read more: 👉 https://tinyurl.com/5crw5faj #Security https://t.co/WfmPJQV1Fn

    Post summary

    Fedora 43 receives a critical update that patches CVE‑2026‑25537, a JWT authentication bypass, along with a DoS issue in the time crate; the advisory links to more details.

    0000050
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkeatsjsonwebtoken-rust-

Explore more