Description
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption Key (CEK) buffer. A remote, unauthenticated attacker who can submit a crafted JWE to an application that decrypts it with an AES-KW symmetric key can trigger an out-of-bounds heap write, corrupting the heap. This leads at minimum to a crash (denial of service) and, depending on the heap layout and allocator, may be leverageable for further memory-corruption impact. `cjose_jwe_import()` / `cjose_jwe_decrypt()` are pre-authentication entry points: they parse and process fully attacker-controlled input. Upgrade to cjose 0.6.2.5 to receive a patch. If upgrading is not immediately possible, reject the AES Key Wrap algorithms (`A128KW`/`A192KW`/`A256KW`) for untrusted JWEs at the application layer.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in the OpenIDC/cjose library’s handling of the AES Key Wrap key‑management algorithms (A128KW, A192KW, A256KW). Before version 0.6.2.5 the decryption path does not validate the length of the attacker‑supplied encrypted_key in a JWE token. This omission allows a crafted JWE to be unwrapped into a fixed‑size heap buffer, resulting in an out‑of‑bounds write. The heap corruption can cause a crash, delivering a denial of service, and in some heap layouts may be leveraged for further memory corruption or code execution.

Affected Systems

OpenIDC’s cjose library is affected, specifically any installation using a version earlier than 0.6.2.5. All applications that employ cjose to decrypt JWEs with AES‑Key Wrap algorithms are potentially impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability that requires remote, unauthenticated input. An attacker can send a crafted JWE to any service that uses cjose to decrypt it, triggering the buffer overflow. While the EPSS score is unavailable, the vulnerability’s nature permits straightforward exploitation in environments where the library is used without additional safeguards. The lack of listing in the CISA KEV catalog does not reduce the risk; the flaw remains in active use and provides a direct remote attack vector that can cause service disruption or potentially lead to arbitrary code execution if heap exploitation succeeds.

Generated by OpenCVE AI on September 9, 2026 at 08:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade cjose to version 0.6.2.5 or later to apply the fix for the buffer overflow.
  • If an upgrade is temporarily infeasible, configure the application to reject AES Key Wrap algorithms (A128KW, A192KW, A256KW) for any JWE tokens it receives from untrusted sources.
  • Implement application‑level validation to ensure that any JWE encrypted_key length matches the expected size before attempting decryption, and only process JWEs that originate from authenticated and trusted origins.

Generated by OpenCVE AI on September 9, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6499-1 cjose security update
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidc
Openidc cjose
Vendors & Products Openidc
Openidc cjose

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 08 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption Key (CEK) buffer. A remote, unauthenticated attacker who can submit a crafted JWE to an application that decrypts it with an AES-KW symmetric key can trigger an out-of-bounds heap write, corrupting the heap. This leads at minimum to a crash (denial of service) and, depending on the heap layout and allocator, may be leverageable for further memory-corruption impact. `cjose_jwe_import()` / `cjose_jwe_decrypt()` are pre-authentication entry points: they parse and process fully attacker-controlled input. Upgrade to cjose 0.6.2.5 to receive a patch. If upgrading is not immediately possible, reject the AES Key Wrap algorithms (`A128KW`/`A192KW`/`A256KW`) for untrusted JWEs at the application layer.
Title OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)
Weaknesses CWE-122
CWE-787
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T16:03:38.312Z

Reserved: 2026-06-11T15:46:12.318Z

Link: CVE-2026-53938

cve-icon Vulnrichment

Updated: 2026-09-09T15:51:51.421Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T00:17:31.557

Modified: 2026-09-10T19:57:48.533

Link: CVE-2026-53938

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-08T23:25:30Z

Links: CVE-2026-53938 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:59Z

Weaknesses