github.com/nats-io/jwt vulnerabilities
CVEs whose affected-version data names the github.com/nats-io/jwt package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-3127Criticalnats-io/jwt not enforcing checking of Import token permissions
nats-io/jwt not enforcing checking of Import token permissions
▾ Midnightnats-io · github.com/nats-io/jwtEPSS 1.4%via OSV
CVE-2020-26892Critical· 9.8Incorrect handling of credential expiry by /nats-io/nats-server
Incorrect handling of credential expiry by /nats-io/nats-server
▾ Midnightnats-io · github.com/nats-io/jwtEPSS 2.1%via OSV