nuget package report

Is System.IdentityModel.Tokens.Jwt safe?

1 known vulnerability, worst severity MODERATE.

cvss
6.8

how bad it is if exploited, out of 10

epss
2.9%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-59j7-ghrg-fj52, the advisory selected below

// advisories

GHSA-59j7-ghrg-fj52

MODERATECVE-2024-21319

A Denial of Service vulnerability exists in ASP.NET Core project templates which utilize JWT-based authentication tokens. This vulnerability allows an unauthenticated client to consume arbitrarily large amounts of server memory, potentially triggering an out-of-memory condition on the server and making the server no longer able to respond to legitimate requests.

Affected
>= 7.0.0-preview, < 7.1.2, >= 6.5.0, < 6.34.0, < 5.7.0
Fixed in
7.1.2
Weakness
CWE-400
Published
2024-01-09
Source
github

GHSANVDMITREreferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.


Checked 2026-09-22 at 01:30 UTC. The most recent advisory here was published 2024-01-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is System.IdentityModel.Tokens.Jwt safe? nuget package security report | CyberXYZ