cjose vulnerabilities
CVEs whose affected-version data names the cjose package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53938High· 8.2OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) do…
▾ TwilightOpenIDC · cjoseEPSS 0.24%via NVD
CVE-2026-53939Critical· 9.1PoCOpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS3…
▾ AbyssalOpenIDC · cjoseEPSS 0.20%via NVD