Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2015-9235: jsonwebtoken library can be exploited when unpatched

CVE-2015-9235 · published 3 days ago
Summary

The jsonwebtoken code used in Node.js applications may let a maliciously crafted token bypass security checks. This affects any project that uses the jsonwebtoken package from the listed sources. Update to the newest released version of the package to protect your system.

What to do
  • Update julien.wollscheid jsonwebtoken to version 4.2.2.
  • Update jsonwebtoken to version 0.1.0-aikido.4.
  • Update rootio @rootio/jsonwebtoken to version 0.1.0-root.io.4.
  • Update julien.wollscheid jsonwebtoken to version 0.1.0-aikido.4.
  • Update auth0 jsonwebtoken to version 4.2.2 or later.
Affected software
Ecosystem VendorProductAffected versions
npm julien.wollscheid jsonwebtoken < 4.2.2
Fix: upgrade to 4.2.2
– auth0 jsonwebtoken < 4.2.2
cpe:2.3:a:auth0:jsonwebtoken:*:*:*:*:*:node.js:*:*
Root:npm – jsonwebtoken < 0.1.0-aikido.4
Fix: upgrade to 0.1.0-aikido.4
Root:npm rootio @rootio/jsonwebtoken < 0.1.0-root.io.4
Fix: upgrade to 0.1.0-root.io.4
Root:npm julien.wollscheid jsonwebtoken < 0.1.0-aikido.4
Fix: upgrade to 0.1.0-aikido.4
Original advisory text
CVE-2015-9235 in jsonwebtoken - Patched by Root
Root has patched CVE-2015-9235 in the jsonwebtoken package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
Exploitation
EPSS 9%
Type
CWE-20Improper Input Validation
CWE-327Use of a Broken Cryptographic Algorithm
Timeline
Published22 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta