CVE-2026-53939 | CVSS: 9.1 | 严重级别: CRITICAL
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the conte
参考链接:
• https://github.com/OpenIDC/cjose/commit/2a6e5bd969fa20059fb00913fb9f57d77ea6a4d9
• https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.6
• https://github.com/OpenIDC/cjose/security/advisories/GHSA-f6wf-pqg3-6wqq
📌 数据来源: NVD 官方