CVE-2025-30144: Fast-JWT Improperly Validates iss Claims
(updated )
The fast-jwt
library does not properly validate the iss
claim based on the RFC https://datatracker.ietf.org/doc/html/rfc7519#page-9.
References
Detect and mitigate CVE-2025-30144 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →