Products: 3
Vulnerabilities: 10
Known Exploited: 0
4
Critical Level Threats
2
High Level Threats
4
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-44351
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
Last Modified: May 14, 2026
Published: May 13, 2026
CVE-2026-35041
ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification
Last Modified: Apr 15, 2026
Published: Apr 09, 2026
CVE-2026-35040
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Last Modified: Apr 17, 2026
Published: Apr 09, 2026
CVE-2026-35042
fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Last Modified: Apr 13, 2026
Published: Apr 06, 2026
CVE-2026-35039
fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Last Modified: Apr 22, 2026
Published: Apr 06, 2026
Items Per Page
