Cisco node-jos < 0.11.0 - Re-sign Tokens

Cisco node-jos < 0.11.0 - Re-sign Tokens

Published 9 Sep 2026Updated 9 Sep 2026186 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

What happened

JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 44324Cisco node-jos < 0.11.0 - Re-sign TokenszioBlack2018-03-20VerifiedSploitusJWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload valuesKitPloit2026-09-10T07:59:46Candidatekitploit.comJWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload valuesen2026-09-10T07:59:46CandidatePoC-in-GitHub · zi0Black/POC-CVE-2018-0114This repository contains the POC of an exploit for node-jose < 0.11.0★ 26zi0Black2018-03-20CandidatePoC-in-GitHub · Logeirs/CVE-2018-0114★ 0Logeirs2020-08-18CandidatePoC-in-GitHub · adityathebe/POC-CVE-2018-0114POC for CVE-2018-0114 written in Go★ 1adityathebe2020-12-20CandidatePoC-in-GitHub · Eremiel/CVE-2018-0114python2.7 script for JWT generation★ 2Eremiel2021-01-03CandidatePoC-in-GitHub · Starry-lord/CVE-2018-0114★ 0Starry-lord2021-01-13CandidatePoC-in-GitHub · scumdestroy/CVE-2018-0114Exploit for Node-jose < 0.11.0 written in Ruby★ 3scumdestroy2021-05-11CandidatePoC-in-GitHub · j4k0m/CVE-2018-0114Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.★ 4j4k0m2021-09-03CandidatePoC-in-GitHub · mmeza-developer/CVE-2018-0114JWT Exploit★ 0mmeza-developer2021-11-06CandidatePoC-in-GitHub · Pandora-research/CVE-2018-0114-Exploit★ 0Pandora-research2022-09-26CandidatePoC-in-GitHub · amr9k8/jwt-spoof-toolAutomate JWT Exploit (CVE-2018-0114)★ 0amr9k82023-03-16CandidatePoC-in-GitHub · z-bool/Venom-JWT针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)★ 288z-bool2025-01-27CandidatePoC-in-GitHub · sealldeveloper/CVE-2018-0114-PoCA PoC of CVE-2018-0114 I made for PentesterLab★ 0sealldeveloper2025-04-25CandidatePoC-in-GitHub · n0m-d/CVE-2018-0114-Go★ 0n0m-d2025-08-14CandidatePoC-in-GitHub · fevra-dev/ClaimJumperProfessional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).★ 1fevra-dev2026-01-16Candidate