CVE-2026-53939 - OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
Brief
CVE ID : CVE-2026-53939
Published : Sept. 9, 2026, 12:17 a. m.
- 33 minutes ago
Description : OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.
- 1 through 0.
- 2.
5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated.
The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.
- 2. 6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`.
