OpenIDC has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.6 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
OpenIDC vulnerabilities
CVEs affecting OpenIDC, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-53938High· 8.2OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) do…
▾ TwilightOpenIDC · cjoseEPSS 0.24%via NVD
CVE-2026-53939Critical· 9.1PoCOpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS3…
▾ AbyssalOpenIDC · cjoseEPSS 0.20%via NVD