VDB

GCVE-110-HSEC-2026-0010

GCVE-110-HSEC-2026-0010
Advisory PublishedCVSS 4.0/10
Vulnetix · Advisory published October 5, 2026
Improper parsing of fractional `NumericDate` from JWT `exp` claims

Weaknesses (CWE)

CWE-681CWE-681CWE-613CWE-613

Risk Scores

CVSS 3.1
4.0/10
Medium · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:W/RC:C/IR:H/MAV:N/MAC:H/MPR:N/MUI:N/MS:C/MC:N/MI:L/MA:N

Affected Products

VendorProductVersionsPlatforms
haskelljwt0.1.0 (affected)—

References

report
patch
advisory

Browse GCVE Records

3,055 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›