High severity7.5NVD Advisory· Published Jan 23, 2017· Updated May 13, 2026
CVE-2016-7037
CVE-2016-7037
Description
The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signatures via a timing attack.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/emarref/jwt/pull/20nvdIssue TrackingPatchThird Party Advisory
- github.com/emarref/jwt/releases/tag/1.0.3nvdIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/95847nvd
News mentions
0No linked articles in our index yet.