The PHP JOSE Project maintains a PHP library for JSON Object Signing and Encryption (JOSE) operations, a narrowly scoped cryptographic utility focused on token handling and message authentication. Its observed vulnerability signal centers on the use of broken or risky cryptographic algorithms, reflecting the tension between supporting legacy standards for compatibility and the evolving security baseline for cryptographic implementations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Jose Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5431HIGH The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification | Aug 7, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Jose Project.
Media articles that mention a CVE ID that affects a product developed by Php Jose Project — matched by CVE ID, not by vendor name.