VYPR
High severity7.7NVD Advisory· Published Jul 1, 2022· Updated Jun 22, 2026

CVE-2022-25898

CVE-2022-25898

Description

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
jsrsasignnpm
>= 4.8.0, < 10.5.2510.5.25

Affected products

3
  • cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:*
    Range: >=4.8.0,<10.5.25
  • jsrsasign/jsrsasigndescription
  • ghsa-coords
    Range: >= 4.8.0, < 10.5.25

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.