jose-jwt is vulnerable to Use of a Broken or Risky Cryptographic Algorithm
77
High Risk
Affected versions of the package may use a broken or risky cryptographic algorithm. In the AES GCM algorithm, the tag length is not enforced to 16. This allows an attacker to provide a truncated authentication tag and modify the JSON Web Encryption (JWE) accordingly, potentially bypassing the integrity checks and tampering with the encrypted data.
You are affected if you are using a version that falls within the vulnerable range.
jose-jwt is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 1.9 - 5.0.0.
Upgrade the jose-jwt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant