# Auth0 node-jws HS256 verification bypass via secret lookup

Source: https://startwithidentity.com/cves/cve-2025-65945/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[auth0/node-jws](https://github.com/auth0/node-jws) below 3.2.3 and 4.0.1 verified HS256 [JWTs](https://startwithidentity.com/glossary/jwt/) incorrectly when the secret was resolved through a user-controlled lookup. An attacker who can influence which secret is chosen can produce a token that verifies. Patched in 3.2.3 and 4.0.1 (December 2025). Public EPSS around disclosure sat near 0.93 percent, which is why some trackers call it medium. The class is still "signature bypass."

## Why it matters

node-jws sits under a lot of Node [OIDC](https://startwithidentity.com/glossary/oidc/) and API-auth code, including stacks that started from [Auth0](https://startwithidentity.com/vendors/ciam/auth0/) samples. A medium CVSS on a JWT library is how "we only accept signed tokens" quietly becomes "we accept the attacker's HMAC." Pair it with [CVE-2025-9485](https://startwithidentity.com/cves/cve-2025-9485/) (WordPress OAuth SSO JWT forgery) and [CVE-2026-48558](https://startwithidentity.com/cves/cve-2026-48558/) (SimpleHelp `alg:none`) and you have the 2025-2026 JWT lesson: verifiers still fail the first test.

## What to do

- Upgrade node-jws to 4.0.1 or 3.2.3. Search transitive deps, not only direct ones.
- Never let the token pick the HMAC secret. Resolve the key from a server-side kid map, then verify.
- Prefer RS256/ES256 with a [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint over HS256 shared secrets for anything that crosses a trust boundary.
- See the [JWT decoder](https://startwithidentity.com/tools/jwt-decoder/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/) for the checks a verifier must not skip.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-65945](https://nvd.nist.gov/vuln/detail/CVE-2025-65945)
- auth0/node-jws security advisory, December 2025
