High severity7.5NVD Advisory· Published Dec 27, 2022· Updated Jun 17, 2026
CVE-2015-10004
CVE-2015-10004
Description
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/robbert229/jwtGo | < 0.0.0-20170426191122-ca1404ee6e83 | 0.0.0-20170426191122-ca1404ee6e83 |
Affected products
3- cpe:2.3:a:json_web_token_project:json_web_token:-:*:*:*:*:go:*:*
Patches
Vulnerability mechanics
References
5- github.com/robbert229/jwt/commit/ca1404ee6e83fcbafb66b09ed0d543850a15b654nvdPatchThird Party AdvisoryWEB
- pkg.go.dev/vuln/GO-2020-0023nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-5vw4-v588-pgv8ghsaADVISORY
- github.com/robbert229/jwt/issues/12nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2015-10004ghsaADVISORY
News mentions
0No linked articles in our index yet.