Impact
OpenIDC cjose, a C library for JOSE, created the content‑encryption key (CEK) as all zero bytes for each AES‑CBC‑HMAC algorithm instance between versions 0.6.1 and 0.6.2.5. As a result, every JWE issued with these algorithms is protected under a publicly known key, allowing anyone who obtains such ciphertext to decrypt it and forge or alter its contents. The weakness lies in improper key generation and randomization, directly undermining the confidentiality and integrity guarantees of the encryption scheme.
Affected Systems
The flaw affects the OpenIDC cjose library, specifically releases 0.6.1 through 0.6.2.5. Any system using cjose to create or parse JWE payloads that employ the A128CBC-HS256, A192CBC-HS384, or A256CBC-HS512 algorithms is impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, reflecting its high severity. The EPSS score is not available and the issue is not yet listed in CISA KEV, but the exploitation path is straightforward: any party who can intercept or otherwise access a JWE encrypted with the vulnerable algorithms can recover the plaintext due to the known zero key, and can consequently forge messages and subvert the integrity of communications. Because the key generation flaw is deterministic and global per library version, the attack can be executed without user interaction or additional system compromise.
OpenCVE Enrichment
Debian DSA