{"id":"CVE-2015-9235","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-9235","summary":"Verification Bypass in jsonwebtoken","details":"Versions 4.2.1 and earlier of `jsonwebtoken` are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm.\n\n\n\n\n## Recommendation\n\nUpdate to version 4.2.2 or later.","published":"2018-10-09T00:38:30Z","modified":"2026-09-10T03:48:15.346337398Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"npm","name":"jsonwebtoken","fixedVersion":"4.2.2"}],"fix":{"url":"https://github.com/auth0/node-jsonwebtoken/commit/1bb584bc382295eeb7ee8c4452a673a77a68b687","label":"auth0/node-jsonwebtoken@1bb584b"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-9235"},{"type":"WEB","url":"https://github.com/auth0/node-jsonwebtoken/commit/1bb584bc382295eeb7ee8c4452a673a77a68b687"},{"type":"WEB","url":"https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c7hr-j4mj-j2w6"},{"type":"WEB","url":"https://www.npmjs.com/advisories/17"},{"type":"WEB","url":"https://www.timmclean.net/2015/02/25/jwt-alg-none.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:48:15.346337398Z"}}