Nearform

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 10
    Known Exploited: 0
    4
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-44351

    fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass

    Last Modified: May 14, 2026
    Published: May 13, 2026

    CVE-2026-35041

    ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification

    Last Modified: Apr 15, 2026
    Published: Apr 09, 2026

    CVE-2026-35040

    fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)

    Last Modified: Apr 17, 2026
    Published: Apr 09, 2026

    CVE-2026-35042

    fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

    Last Modified: Apr 13, 2026
    Published: Apr 06, 2026

    CVE-2026-35039

    fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)

    Last Modified: Apr 22, 2026
    Published: Apr 06, 2026
    Items Per Page
    Nearform Vulnerabilities & Security CVEs | CVE-DB