jose vulnerabilities
CVEs whose affected-version data names the jose package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-89086Critical· 9.1PoCIn the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
▾ AbyssalOCaml · joseEPSS 0.20%via NVD
CVE-2026-34240High· 7.5JOSE is a Javascript Object Signing and Encryption (JOSE) library
JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header…
▾ Twilightappsup-dart · joseEPSS 0.13%via NVD