libjwt CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

libjwt vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to libjwt, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-33996 LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity o [email protected] 5.8 0.15% 2026-03-27 2026-06-17
CVE-2024-25189 libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel. [email protected] 9.8 0.95% 2024-02-08 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence