joserfc has 4 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 6.4 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- joserfc 4
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-65015Criticaljoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads52CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)41CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)41CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization29
joserfc vulnerabilities
CVEs affecting joserfc, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV
CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
▾ Sunlitjoserfc · joserfcEPSS 0.16%via OSV
CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
▾ Twilightjoserfc · joserfcEPSS 0.43%via OSV
CVE-2025-65015Criticaljoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
▾ Midnightjoserfc · joserfcEPSS 0.41%via OSV