{"id":"GHSA-9gxv-x7rp-r2hc","summary":"gree/jose - \"None\" Algorithm treated as valid in tokens","details":"Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).","modified":"2026-07-16T19:00:30.760156435Z","published":"2024-05-15T21:47:39Z","database_specific":{"github_reviewed_at":"2024-05-15T21:47:39Z","nvd_published_at":null,"cwe_ids":["CWE-327","CWE-347"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries"},{"type":"WEB","url":"https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/gree/jose/2016-08-30.yaml"},{"type":"PACKAGE","url":"https://github.com/nov/jose-php"},{"type":"WEB","url":"https://github.com/nov/jose-php/compare/2.2.0...2.2.1"}],"affected":[{"package":{"name":"gree/jose","ecosystem":"Packagist","purl":"pkg:composer/gree/jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.1"}]}],"versions":["0.1.0","0.1.1","0.1.3","0.1.4","0.1.5","1.0.0","1.0.1","2.0.0","2.0.1","2.1.0","2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-9gxv-x7rp-r2hc/GHSA-9gxv-x7rp-r2hc.json"}}],"schema_version":"1.9.0"}