OktaOKTA-0RXNV4B
Improper HMAC Signature Verification in auth0/node-jws CVE-2025-65945 - Dec 4, 2025
UnratedCVE-2025-65945 · Published Dec 4, 2025
An improper signature verification vulnerability exists when using auth0/node-jws with the HS256 algorithm under specific conditions. To remediate, upgrade auth0/node-jws version to version 3.2.3 or 4.0.1.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 1 | Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1... | Unrated | No fix yet |
| Dec 102025 | Race condition in the Okta Java SDK CVE-2025-67505 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025 | Unrated | No fix yet |
| Oct 12025 | Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769... | Unrated | No fix yet |