CVE-2016-5429: Jose-PHP Project Jose-PHP

Low severity, CVSS 3.7. EPSS: 1.3% chance of exploitation in the next 30 days.

jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.

Affected products

Published 2016-09-03. Last modified 2026-06-17.