---
id: CVE-2026-34240
title: JOSE is a Javascript Object Signing and Encryption (JOSE) library
summary: >-
  JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to
  version 0.3.5+1, a vulnerability in jose could allow an unauthenticated,
  remote attacker to forge valid JWS/JWT tokens by using a key embedded in the
  JOSE header…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-347
vendor: appsup-dart
product: jose
affected:
  - jose < 0.3.5\+1
patched:
  - jose 0.3.5\+1
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34240'
references:
  - url: >-
      https://github.com/appsup-dart/jose/commit/b07799aac1f56a9a21483feac026272aab30cc5d
    label: security-advisories@github.com
  - url: >-
      https://github.com/appsup-dart/jose/security/advisories/GHSA-vm9r-h74p-hg97
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00192
epssPercentile: 0.07857
ingestedAt: '2026-07-24T20:38:02.494Z'
---

## Overview

JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matching private key. Applications using affected versions for token verification are impacted. This issue has been patched in version 0.3.5+1. A workaround for this issue involves rejecting tokens where header jwk is present unless that jwk matches a key already present in the application's trusted key store.

## Affected

- `jose < 0.3.5\+1`

## Remediation

Upgrade past the affected range:

- `jose 0.3.5\+1`
