Start with Identity
Identity CVE · OAuth / OIDC / JWT

CVE-2025-65945Auth0 node-jws HS256 verification bypass via secret lookup

medium
Product: auth0/node-jwsVendor: Auth0 / OktaCWE-347Disclosed: 2025-12-04Status: PatchedProtocol deep diveNVD ↗

What broke

auth0/node-jws below 3.2.3 and 4.0.1 verified HS256 JWTs incorrectly when the secret was resolved through a user-controlled lookup. An attacker who can influence which secret is chosen can produce a token that verifies. Patched in 3.2.3 and 4.0.1 (December 2025). Public EPSS around disclosure sat near 0.93 percent, which is why some trackers call it medium. The class is still "signature bypass."

Why it matters

node-jws sits under a lot of Node OIDC and API-auth code, including stacks that started from Auth0 samples. A medium CVSS on a JWT library is how "we only accept signed tokens" quietly becomes "we accept the attacker's HMAC." Pair it with CVE-2025-9485 (WordPress OAuth SSO JWT forgery) and CVE-2026-48558 (SimpleHelp alg:none) and you have the 2025-2026 JWT lesson: verifiers still fail the first test.

What to do

  • Upgrade node-jws to 4.0.1 or 3.2.3. Search transitive deps, not only direct ones.
  • Never let the token pick the HMAC secret. Resolve the key from a server-side kid map, then verify.
  • Prefer RS256/ES256 with a JWKS endpoint over HS256 shared secrets for anything that crosses a trust boundary.
  • See the JWT decoder and the validate a JWT recipe for the checks a verifier must not skip.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.