Vulnerability DatabaseGHSA-g3qw-9pgp-xpj4

GHSA-g3qw-9pgp-xpj4
JavaScript vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-g3qw-9pgp-xpj4) affects the njwt npm package, specifically versions prior to 1.0.0. This security issue was discovered and published to the GitHub Advisory Database on September 1, 2020, with the latest update on January 9, 2023. The vulnerability is classified as low severity and is identified as an out-of-bounds read vulnerability (GitHub Advisory).

Technical details

The vulnerability is categorized as CWE-125 (Out-of-bounds Read) and occurs when a number is passed into the base64urlEncode function of the njwt package. The technical implementation details reveal that the vulnerability manifests differently depending on the Node.js version being used (GitHub Advisory).

Impact

The impact of this vulnerability varies based on the Node.js version in use. On Node.js 6.x or lower, the vulnerability can lead to exposure of sensitive information. For all other versions of Node.js, the vulnerability creates a potential Denial of Service condition (GitHub Advisory).

Exploitability

The vulnerability is triggered when a number is passed into the base64urlEncode function of the affected njwt versions. The specific exploitation method involves manipulating the input to the base64urlEncode function to cause an out-of-bounds read condition (GitHub Advisory).

Mitigation and workarounds

The recommended mitigation is to upgrade to njwt version 1.0.0 or later, which contains the fix for this vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63376HIGH8.2
  • JavaScript logoJavaScript
  • cockpit-image-builder.src
NoYesSep 03, 2026
GHSA-7q9c-hpx7-9cwmHIGH7.5
  • JavaScript logoJavaScript
  • @typespec/spector
NoYesSep 04, 2026
CVE-2026-77465HIGH7.5
  • JavaScript logoJavaScript
  • toml
NoYesSep 03, 2026
CVE-2026-71429MEDIUM6.2
  • JavaScript logoJavaScript
  • stream-json
NoYesSep 03, 2026
GHSA-6hxq-p678-4hr2LOW2
  • JavaScript logoJavaScript
  • @simplewebauthn/server
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management