CVE-2026-53938
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Overflow in cjose JWE Decryption

Vulnerability report for CVE-2026-53938, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption Key (CEK) buffer. A remote, unauthenticated attacker who can submit a crafted JWE to an application that decrypts it with an AES-KW symmetric key can trigger an out-of-bounds heap write, corrupting the heap. This leads at minimum to a crash (denial of service) and, depending on the heap layout and allocator, may be leverageable for further memory-corruption impact. `cjose_jwe_import()` / `cjose_jwe_decrypt()` are pre-authentication entry points: they parse and process fully attacker-controlled input. Upgrade to cjose 0.6.2.5 to receive a patch. If upgrading is not immediately possible, reject the AES Key Wrap algorithms (`A128KW`/`A192KW`/`A256KW`) for untrusted JWEs at the application layer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openidc cjose to 0.6.2.5 (exc)
openidc cjose 0.6.2.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap buffer overflow vulnerability in the cjose library's AES Key Wrap decryption functionality. When decrypting JWEs using AES-KW algorithms (A128KW, A192KW, A256KW), the library fails to validate the length of the attacker-supplied encrypted_key before unwrapping it into a fixed-size heap buffer for the Content Encryption Key (CEK). This allows a remote attacker to craft a malicious JWE with an oversized encrypted_key, causing an out-of-bounds heap write.

Detection Guidance

To detect this vulnerability, check the version of the cjose library installed on your system. Run: 'cjose --version' or inspect package managers like 'dpkg -l | grep cjose' (Debian/Ubuntu) or 'rpm -qa | grep cjose' (RHEL). If the version is 0.6.2.4 or earlier, the system is vulnerable.

Impact Analysis

The impact includes at minimum a crash (denial of service) due to heap corruption. Depending on the heap layout and memory allocator, it may also be possible for an attacker to achieve further memory corruption, potentially leading to code execution or other malicious outcomes.

Compliance Impact

This vulnerability primarily impacts availability due to potential denial of service from crashes. It may also affect integrity if exploited for further memory corruption. GDPR requires ensuring data availability and integrity, while HIPAA mandates protecting data integrity and availability. The vulnerability could lead to unauthorized data access or corruption if exploited, potentially violating these requirements.

Mitigation Strategies

Immediately upgrade the cjose library to version 0.6.2.5 or later. If upgrading is not possible, configure applications to reject AES Key Wrap algorithms (A128KW, A192KW, A256KW) for untrusted JWEs at the application layer.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53938. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart