Impact
The vulnerability arises in the OpenIDC/cjose library’s handling of the AES Key Wrap key‑management algorithms (A128KW, A192KW, A256KW). Before version 0.6.2.5 the decryption path does not validate the length of the attacker‑supplied encrypted_key in a JWE token. This omission allows a crafted JWE to be unwrapped into a fixed‑size heap buffer, resulting in an out‑of‑bounds write. The heap corruption can cause a crash, delivering a denial of service, and in some heap layouts may be leveraged for further memory corruption or code execution.
Affected Systems
OpenIDC’s cjose library is affected, specifically any installation using a version earlier than 0.6.2.5. All applications that employ cjose to decrypt JWEs with AES‑Key Wrap algorithms are potentially impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability that requires remote, unauthenticated input. An attacker can send a crafted JWE to any service that uses cjose to decrypt it, triggering the buffer overflow. While the EPSS score is unavailable, the vulnerability’s nature permits straightforward exploitation in environments where the library is used without additional safeguards. The lack of listing in the CISA KEV catalog does not reduce the risk; the flaw remains in active use and provides a direct remote attack vector that can cause service disruption or potentially lead to arbitrary code execution if heap exploitation succeeds.
OpenCVE Enrichment
Debian DSA