All 3 CVE vulnerabilities found in cjose, with AI-generated Chinese analysis, references, and POCs.
Vendor: OpenIDC
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53939 | OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption CWE-321 | 9.1 | Critical | 2026-09-08 |
| CVE-2026-53938 | OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW) CWE-122 | 8.2 | High | 2026-09-08 |
| CVE-2023-37464 | Incorrect Authentication Tag length usage in AES GCM decryption in OpenIDC/cjose CWE-327 | 8.6 | High | 2023-07-14 |
All 3 known CVE vulnerabilities affecting cjose with full Chinese analysis, references, and POCs where available.