VDB
Sign up
CRITICAL

GHSA-h533-5v22-8vcp

firebase/php-jwt: "None" Algorithm treated as valid on tokens

Quick fix

GHSA-h533-5v22-8vcp — firebase/php-jwt: upgrade to the fixed version with the command below.

composer require firebase/php-jwt:^2.0.0

Details

Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/firebase/php-jwt
Introduced in: 0Fixed in: 2.0.0
Fixcomposer require firebase/php-jwt:^2.0.0

References