web-token/jwt-library vulnerabilities
CVEs whose affected-version data names the web-token/jwt-library package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
GHSA-6vvh-pxr4-25r7MediumPHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
▾ Sunlitweb-token · web-token/jwt-experimentalvia GHSA
GHSA-3prj-6hqw-cm82HighPHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
▾ Twilightweb-token · web-token/jwt-libraryvia GHSA
GHSA-jc38-x7x8-2xc8HighPHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks
PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks
▾ Twilightweb-token · web-token/jwt-frameworkvia GHSA
GHSA-5739-39v2-5754MediumPHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
▾ Sunlitweb-token · web-token/jwt-libraryvia GHSA