gree/jose
JWT, JWS and JWS implementation in PHP
Activity
- Latest release
- 10y ago
- Total releases
- 12
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 25, 2013
| Version | Released | |
|---|---|---|
2.2.1
patch
deprecated
| ||
2.2.0
minor
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.1
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.5
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.4
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
GHSA-9gxv-x7rp-r2hc
May 15, 2024
gree/jose - "None" Algorithm treated as valid in tokens
Critical
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512). Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References
Updated Jul 16, 2026 · Source: OSV.dev
CVE-2016-5431
GHSA-xm5f-hc9r-76f3
May 24, 2022
PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
1.0.0
1.0.1
2.0.0
2.0.1
2.1.0
2.2.0
Fixed in
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev |