Description
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).
Published: 2026-09-08
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: JWE confidentiality and integrity compromise
Action: Apply Patch
AI Analysis

Impact

OpenIDC cjose, a C library for JOSE, created the content‑encryption key (CEK) as all zero bytes for each AES‑CBC‑HMAC algorithm instance between versions 0.6.1 and 0.6.2.5. As a result, every JWE issued with these algorithms is protected under a publicly known key, allowing anyone who obtains such ciphertext to decrypt it and forge or alter its contents. The weakness lies in improper key generation and randomization, directly undermining the confidentiality and integrity guarantees of the encryption scheme.

Affected Systems

The flaw affects the OpenIDC cjose library, specifically releases 0.6.1 through 0.6.2.5. Any system using cjose to create or parse JWE payloads that employ the A128CBC-HS256, A192CBC-HS384, or A256CBC-HS512 algorithms is impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.1, reflecting its high severity. The EPSS score is not available and the issue is not yet listed in CISA KEV, but the exploitation path is straightforward: any party who can intercept or otherwise access a JWE encrypted with the vulnerable algorithms can recover the plaintext due to the known zero key, and can consequently forge messages and subvert the integrity of communications. Because the key generation flaw is deterministic and global per library version, the attack can be executed without user interaction or additional system compromise.

Generated by OpenCVE AI on September 9, 2026 at 08:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the OpenIDC cjose library to version 0.6.2.6 or later, where CEKs are generated with a secure random source.
  • For ciphertexts already produced with the vulnerable library, re‑encrypt them using a newer library version or rotate any secrets they protected, and replace the compromised data in all relevant systems.
  • If an upgrade is temporarily infeasible, avoid the affected algorithms by configuring JWE encryption to use AES‑GCM variants (A128GCM, A192GCM, A256GCM) or by supplying your own key with alg=dir; otherwise, refrain from using cjose for JWE encryption until the patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 08:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6499-1 cjose security update
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidc
Openidc cjose
Vendors & Products Openidc
Openidc cjose

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).
Title OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
Weaknesses CWE-321
CWE-330
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:12:15.459Z

Reserved: 2026-06-11T15:46:12.318Z

Link: CVE-2026-53939

cve-icon Vulnrichment

Updated: 2026-09-09T15:11:55.354Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T00:17:31.700

Modified: 2026-09-10T19:57:48.533

Link: CVE-2026-53939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:57Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key

  • CWE-330

    Use of Insufficiently Random Values