VYPR

cjose

by Zmartzone

Source repositories

CVEs (3)

  • CVE-2026-53939CriSep 9, 2026
    risk 0.52cvss 9.1epss 0.00

    OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any…

  • CVE-2026-53938HigSep 9, 2026
    risk 0.46cvss 8.2epss 0.00

    OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the…

  • CVE-2023-37464HigJul 14, 2023
    risk 0.00cvss 8.6epss 0.01

    OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied.…