Skip to content

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

High severity GitHub Reviewed Published May 13, 2026 in jwt/ruby-jwt • Updated Jun 2, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts