web-token/jwt-framework
JSON Object Signing and Encryption library for PHP and Symfony Bundle.
Security Advisories for web-token/jwt-framework in packagist
Moderate
about 9 hours ago
PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
packagist
web-token/jwt-library, web-token/jwt-framework
High
about 9 hours ago
PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks
packagist
web-token/jwt-library, web-token/jwt-framework
High
about 9 hours ago
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
packagist
web-token/jwt-library, web-token/jwt-framework