VYPR

PHP JWT

by Zihanggao

CVEs (1)

  • CVE-2024-25191CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.