Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nearform — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting nearform. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nearform specializes in developing high-performance software solutions, with a focus on Node.js and enterprise applications. Historically, their products have been associated with vulnerabilities like remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and insecure dependencies. While no major security incidents have been publicly documented, the 8 CVEs on record highlight recurring issues in component security and access controls. Their codebase typically emphasizes performance but has shown susceptibility to common web vulnerabilities, particularly in server-side request forgery and insecure deserialization. Security researchers note that while Nearform addresses reported flaws promptly, their complex architecture occasionally introduces exploitable misconfigurations in production environments.

Found 14 results / 15 Clear Filters
Top products by nearform: fast-jwt get-jwks
CVE ID Title CVSS Severity Published
CVE-2026-107724 fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery — fast-jwt CWE-347 7.4 High 2026-10-08
CVE-2026-107723 fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array — fast-jwt CWE-1287 8.1 High 2026-10-08
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion — fast-jwt CWE-347 9.8 Critical 2026-10-08
CVE-2026-107721 fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache) — fast-jwt CWE-613 5.9 Medium 2026-10-08
CVE-2026-107720 fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set — fast-jwt CWE-20 7.4 High 2026-10-08
CVE-2026-107719 fast-jwt: Verifier cache accepts expired JWTs without iat. — fast-jwt CWE-613 4.2 Medium 2026-10-08
CVE-2026-44351 fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass — fast-jwt CWE-287 9.1 Critical 2026-05-13
CVE-2026-35041 ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification — fast-jwt CWE-1333 4.2 Medium 2026-04-09
CVE-2026-35040 fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS) — fast-jwt CWE-697 5.3 Medium 2026-04-09
CVE-2026-35042 fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) — fast-jwt CWE-345 7.5 High 2026-04-06
CVE-2026-35039 fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup) — fast-jwt CWE-345 9.1 Critical 2026-04-06
CVE-2026-34950 fast-jwt has an incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key — fast-jwt CWE-327 9.1 Critical 2026-04-06
CVE-2025-30144 Fast-JWT Improperly Validates iss Claims — fast-jwt CWE-345 6.5 Medium 2025-03-19
CVE-2023-48223 fast-jwt JWT Algorithm Confusion — fast-jwt CWE-20 5.9 Medium 2023-11-20

This page lists every published CVE security advisory associated with nearform. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.