CVE-2017-10862: Really Jwt-Scala

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.

Affected products

  • Really Jwt-Scala: up to and including 1.2.2

Published 2017-10-12. Last modified 2026-06-17.