7.5
CVSS V3
Status
Impact
Upstream still relies on this outdated dependency. Since there's no jwt v3 fix for the CVE, upstream must update their code and dependencies to use a newer jwt version.
Status
Impact
v3 is not supported any longer (the last commit on https://github.com/golang-jwt/jwt/tree/v3 was 4 years ago), so it won't be fixed.
Status