Security: jedisct1/rust-jwt-simple
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
rust-jwt-simple accepts expired tokens when a negative timestamp wraps to a far-future valueGHSA-gwc4-h77p-37cw published
Jul 30, 2026 by jedisct1Moderate -
rust-jwt-simple ignores max_validity when a token omits the issued-at claimGHSA-vrcj-2fw8-5wm6 published
Jul 30, 2026 by jedisct1Moderate -
rust-jwt-simple skips JWT claim validation when decrypting JWE tokens with default optionsGHSA-vgc9-f48j-3xvj published
Jul 30, 2026 by jedisct1High
Learn more about advisories related to jedisct1/rust-jwt-simple in the GitHub Advisory Database