A malicious account can create and sign a User JWT which causes a panic when decoded by the NATS JWT library.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0402" }
{ "imports": [ { "path": "github.com/nats-io/jwt", "symbols": [ "Account.Validate", "AccountClaims.Validate", "Export.Validate", "Exports.Validate", "Import.Validate", "Imports.Validate" ] } ] }