Junglewise Threat Intelligence

CVE-2026-53939: OpenIDC cjose all-zero CEK in AES-CBC-HMAC encryption

CVE-2026-53939 · Severity: critical · CVSS 9.1 · Published 2026-09-09

Vendors: Openidc.

Executive brief

OpenIDC cjose is a cryptographic library used to encrypt sensitive data using industry-standard JOSE (JSON Object Signing and Encryption) protocols. A critical flaw caused the library to encrypt data using a fixed, publicly known all-zero encryption key instead of generating random keys when using certain AES-CBC-HMAC algorithms. This means anyone obtaining an encrypted message can decrypt and forge it, completely compromising the confidentiality and integrity of protected data.

Technical details

The vulnerability is a cryptographic key generation failure in the AES-CBC-HMAC content-encryption code path. The `_cjose_jwe_set_cek_aes_cbc()` function inverted the `random` parameter when allocating the content-encryption key (CEK), causing it to zero-fill the key instead of generating random bytes via `RAND_bytes()`. This affects JWE encryption using AES-CBC-HMAC algorithms (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) combined with any key-management algorithm except `dir`, including RSA-OAEP, RSA1_5, and AES-KW variants. The resulting ciphertexts are encrypted and authenticated under an all-zero key. AES-GCM and `dir`-mode encryption paths were unaffected. The vulnerability was fixed in version 0.6.2.6 by correcting the parameter passed to `_cjose_jwe_malloc()` and is demonstrated by regression tests confirming CEK randomness across encryptions. Data already encrypted with the zero key cannot be secured retroactively without re-encryption.

Affected products

  • OpenIDC cjose 0.6.1 through 0.6.2.5

Timeline

  • 2026-09-09: disclosed

References

Related threats