{"id":"CVE-2016-5431","aliases":["GHSA-xm5f-hc9r-76f3"],"url":"https://o3.security/vulnerability/CVE-2016-5431","summary":"PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm","details":"The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.","published":"2019-08-07T15:15:11.783Z","modified":"2026-07-08T12:52:54.083321Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00929,"percentile":0.58898,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"gree/jose","fixedVersion":"2.2.1"}],"fix":{"url":"https://github.com/nov/jose-php/commit/1cce55e27adf0274193eb1cd74b927a398a3df4b","label":"nov/jose-php@1cce55e"},"references":[{"type":"FIX","url":"https://github.com/nov/jose-php/commit/1cce55e27adf0274193eb1cd74b927a398a3df4b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:52:54.083321Z"}}