CVE Database
/

CVE-2015-10004

Back to search

CVE-2015-10004

Published: Dec 27, 2022

Modified: Apr 11, 2025

PUBLISHED

Description

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.

VendorProductVersions

github.com/robbert229/jwt

github.com/robbert229/jwt

affected
0 - < 0.0.0-20170426191122-ca1404ee6e83

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now