Web Hack List

Later archive addition

Critical vulnerability in JSON Web Encryption (JWE) - RFC 7516

The article applies the classic invalid-curve attack to JWE ECDH-ES implementations that fail to validate an attacker's ephemeral public key. Repeated chosen JWEs and a decryption oracle reveal residues of the recipient's static private key, which are combined to recover it; the post includes demo code and affected libraries.

Record

Researcher
Antonio Sanso
Published by
Into The Symmetry

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Antonio Sanso, first published at the original source. Preserved copies are kept so the citation survives its host.