JOSE: missing RSA signature verification
The jose package for OCaml versions before 0.11.0 does not properly verify RSA signatures. It only checks the encoding format (PKCS1) but fails to validate the signature against the public key, allowing attackers to forge tokens by mixing payloads and signatures. This vulnerability was fixed in version 0.11.0.
AI Analysis
Technical Summary
The jose package (versions <0.11.0) fails to validate RSA signatures correctly. While it verifies that the signature encoding is PKCS1, it does not perform cryptographic verification with the public key. This allows an attacker to create forged tokens by combining parts of different signed tokens, bypassing signature validation. The issue was privately reported on 2026-08-25, fixed shortly thereafter, and patched in jose 0.11.0 released on 2026-09-04.
Potential Impact
An attacker can forge JWT tokens by mixing payloads and signatures from different tokens without possessing the private key. This leads to a complete bypass of signature verification, allowing impersonation or privilege escalation. The vulnerability has a critical CVSS score of 9.1, indicating high confidentiality and integrity impact with no availability impact.
Mitigation Recommendations
Upgrade to jose version 0.11.0 or later, where the RSA signature verification issue is fixed. There is no known workaround for affected versions prior to this patch.
JOSE: missing RSA signature verification
Description
The jose package for OCaml versions before 0.11.0 does not properly verify RSA signatures. It only checks the encoding format (PKCS1) but fails to validate the signature against the public key, allowing attackers to forge tokens by mixing payloads and signatures. This vulnerability was fixed in version 0.11.0.
CVSS v3.1
Score 9.1critical
Affected software
pkg:opam/joseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The jose package (versions <0.11.0) fails to validate RSA signatures correctly. While it verifies that the signature encoding is PKCS1, it does not perform cryptographic verification with the public key. This allows an attacker to create forged tokens by combining parts of different signed tokens, bypassing signature validation. The issue was privately reported on 2026-08-25, fixed shortly thereafter, and patched in jose 0.11.0 released on 2026-09-04.
Potential Impact
An attacker can forge JWT tokens by mixing payloads and signatures from different tokens without possessing the private key. This leads to a complete bypass of signature verification, allowing impersonation or privilege escalation. The vulnerability has a critical CVSS score of 9.1, indicating high confidentiality and integrity impact with no availability impact.
Mitigation Recommendations
Upgrade to jose version 0.11.0 or later, where the RSA signature verification issue is fixed. There is no known workaround for affected versions prior to this patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- OSEC-2026-19
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["opam"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6aa2af58acd9273b4925a315
Added to database: 09/10/2026, 13:23:36 UTC
Last enriched: 09/10/2026, 13:26:39 UTC
Last updated: 09/10/2026, 15:30:09 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.