7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Description
CVE-2025-65945: node-jws Signature Bypass This is a proof of concept for a signature verification bypass in the node-jws library. The bug lets attackers forge valid JWTs when the server derives HMAC secrets from user-controlled data. What's the bug?...
Basic Information
ID
0F27C219-7545-58CE-9AB3-D57541856B70
Published
Dec 17, 2025 at 15:52
Modified
Dec 17, 2025 at 16:00