jwe
A Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard
Activity
- Latest release
- 1y ago
- Total releases
- 9
- Cadence
- ~7 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 13, 2016
| Version | Released | |
|---|---|---|
1.1.1
patch
| ||
1.1.0
minor
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2025-54887
GHSA-c7p4-hx26-pr73
Aug 07, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
OverviewThe authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. Impact
Am I Affected?You are affected by this vulnerability even if you do not use an PatchesThe version 1.1.1 fixes the issue by adding the tag length check for the Important: As the GHASH key could have leaked, you must rotate the encryption keys after upgrading to version 1.1.1. ReferencesAffected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.0
1.0.0
1.1.0
Fixed in
1.1.1
References
Updated Aug 08, 2025 · Source: OSV.dev |