GHSA-58f5-hfqc-jgch — jose
MEDIUMGHSA-58f5-hfqc-jgch is a medium-severity (CVSS 5.9) CWE-203 vulnerability in jose. A fix is available for jose — see the affected versions and patch details below.
Padding Oracle Attack due to Observable Timing Discrepancy in jose
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-58f5-hfqc-jgch by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
josenpmDescription
jose is an npm library providing a number of cryptographic operations.
Impact
AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed JWEDecryptionFailed would be thrown. But a possibly observable difference in timing when padding error would occur while decrypting the ciphertext makes a padding oracle and an adversary might be able to make use of that oracle to decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block).
Patches
All major release versions have had a patch released which ensures the HMAC tag is verified before performing CBC decryption. The fixed versions are ^1.28.1 || ^2.0.5 || >=3.11.4.
Users should upgrade their v1.x dependency to ^1.28.1, their v2.x dependency to ^2.0.5, and their v3.x dependency to ^3.11.4
Credits
Thanks to Morgan Brown of Microsoft for bringing this up and Eva Sarafianou (@esarafianou) for helping to score this advisory.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | jose | ≥ 1.0.0&&< 1.28.1 | 1.28.1npm install jose@1.28.1 |
| 📦npm | jose | ≥ 2.0.0&&< 2.0.5 | 2.0.5npm install jose@2.0.5 |
| 📦npm | jose | ≥ 3.0.0&&< 3.11.4 | 3.11.4npm install jose@3.11.4 |
Affected Products
josepanvaDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for jose, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update jose to 1.28.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-58f5-hfqc-jgch is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Frequently Asked Questions
Is GHSA-58f5-hfqc-jgch in your dependencies?
Find it across npm, including transitive dependencies.