VDB
Sign up
CRITICAL

GHSA-4rr6-gf59-ggw5

namshi/jose - Verification bypass

Quick fix

GHSA-4rr6-gf59-ggw5 — namshi/jose: upgrade to the fixed version with the command below.

composer require namshi/jose:^2.2.0

Details

Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/namshi/jose
Introduced in: 0Fixed in: 2.2.0
Fixcomposer require namshi/jose:^2.2.0

References