{"id":"CVE-2024-54150","summary":"Algorithm Confusion Vulnerability in cjwt","details":"cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to exploit the lack of distinction between signing methods.  If the system doesn't differentiate between an HMAC signed token and an RS/EC/PS signed token during verification, it becomes vulnerable to this kind of attack. For instance, an attacker could craft a token with the alg field set to \"HS256\" while the server expects an asymmetric algorithm like \"RS256\". The server might mistakenly use the wrong verification method, such as using a public key as the HMAC secret, leading to unauthorised access. For RSA, the key can be computed from a few signatures. For Elliptic Curve (EC), two potential keys can be recovered from one signature. This can be used to bypass the signature mechanism if an application relies on asymmetrically signed tokens. This issue has been addressed in version 2.3.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-9h24-7qp5-gp82"],"modified":"2026-08-12T15:15:46.720808Z","published":"2024-12-19T18:22:33.901Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54150.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54150.json"},{"type":"ADVISORY","url":"https://github.com/xmidt-org/cjwt/security/advisories/GHSA-9h24-7qp5-gp82"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-54150"},{"type":"FIX","url":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xmidt-org/cjwt","events":[{"introduced":"0"},{"fixed":"096ab3e37f73c914b716e7259589179f363265fd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.3.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.2.0","v2.1.1","v2.1.0","v2.0.1","v2.0.0","v1.0.4","v1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-54150.json","vanir_signatures_modified":"2026-08-12T15:15:46Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["43730075659863917619769323705269155445","144184585020106307495595742242813106950","295755577088363779366320583813714424659","132079437513621315641783711536765751097","61706870210856533280363672476917826311","99719793615952972021825508084652414349","138639367338878393494344758597352036707","158156036253206406512441823724172401430","125209963472721811591947934013657918542","49796977798039003175725891918083101078","72023765152143814001794802416568257653","216853286955092370350155290526535217585","101005358235515767352551414114029442218","122903546960770523052877850222160004168","203238316526322657932179613518614159935","247398635031409898638278697304677138047","23374905940047856718896168507613994839","203887712019183913061002184653201665931","288519522569222163810006429623340219506","108807083757668696046255748424925476770","329618277732599150989794060305105094515","253168424416567180855141802674699111267","293663687614535154384799167341943826195","322386398645446755954066675976786439414","221137476356177259657790135425283698486","173307780779166019993135133847839448412","41568712310294264257325949408519623562","236733344416645463283103055443404607629","237420276945479956595205438941470333579"],"threshold":0.9},"id":"CVE-2024-54150-886256b5","signature_type":"Line","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"src/cjwt.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"tests/test_cjwt_new.c","function":"test_case"},"deprecated":false,"digest":{"function_hash":"52950193658093564129416580692675510721","length":886},"id":"CVE-2024-54150-ad8756ff"},{"digest":{"line_hashes":["33640377083377052897053018126033874593","71273652128956945468829828607889793049","142207204070987864608076448055233914665","150685827742322284871424285247663449741","121877980831699175967339715142850286384","331654466552202658728072930829141966508","273242646522368443754751195699438083185","42687802873637918996085785299502129395","83489426690322610099898393208396988340","298987772829617779229094261523388946027","276128714284502378580531321874406991563","139171872549677176537939819922663831480","285957993962549877563827819808444084954","111699089211024375276540464734302998055","80050935500778597983136903991273651582","34291839660542303354498055445980343758","148412574075737163035972998955686946284","255641663428461944514320296128280548253","212634729884353061366778892173857752968","49004692784409036715890995134332339405","329742195732122250660511526302086110062","180956085963500966190489686957834001580","53727682397370202808733125434754627574","103924482417192966536908166211523948047","69255364447289538514229515004598011660","185818523272088604796193149419525858713","248674816935111134563169028932825035439","332392319129511860031434469424792979860","192750510487348928101530695180341749084","310240465904015018766152236057690776189","17349146891040618901309510018824154055","297463544640302370685890857004063745202","137198599255830308016116723672178727604","284668910855422627226427193760027357616","739789766197252017522130819865057493","100353343536996431753083929556041422446","157296490830406287645986678195941648184","201156580390942160504683390879266807485","76476835798243742620504897836705463685","235713353102914746423651701448735241922","35806965431966953000534373044937076410","221952231878226190819636994835754669041","191564905401941370341201630198943758118","100409346118637395586112250495289319119","267906780984666071085429260454534041994","244841723811298122398521310161893641364","327867294168810982244707371470157522091","83752820857740669035981373513933565538","262843971997948952115873133372675898055","79997026381722191614970928725797761173","83092907454905673114110451038744266856","216562907137160014429106514915075136400","259744567708050851660723456799974012041","324494234957044782634237631017096020312","200045736530336198502391191107260006802","77475352078890832036653446984668377450","294493190723794817319646859617803771771","318862212103525776494186374777106180341","60578809866245247590565334975309431384","297740089156629114533591522238460975168","125825347617131439330069664366929077586","81036881147123583284808841506026435433","172999348733986120572214318568649257772","194793550402292585808588693441230369854","326338240659309728936684181393975325285","209530929774689194453827138156075364962","50380297760941885766949433310733465635","223189808018375774246946483241307442712","322996216853682631437977527992785001951","210145414546233333678562347924871122546","307757899567672202351148182089467686612"],"threshold":0.9},"id":"CVE-2024-54150-e25b4d9c","signature_type":"Line","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"tests/test_cjwt_new.c"},"deprecated":false},{"digest":{"line_hashes":["50046902546088369328877961642625511541","181414919955253410686754378839317888049","102491968831673808256431975296463226949","146184516560887488949479072981245070126","136646273473859446952677241672870617173","273542259857022306304259543053420228386","311185127387899835779000673773642911549","257668368929219643476077085785507638026","113306200198204094547571643149716555832","262238184833689824625783797872739768325","304643724691076769030142234096925777193","281084733299790820604968442021395660342","155387063574254333417966156166283658727","215379229212343476125418019269985979556","130705383024956978584138415413830650094","43358712481534114929325556637844491055","195814919327852002179808385005804058166","236971583122389394048128170354101836091","40077437267419164802541405570796212665","148000997257354109183055681020487226240","81313698853582008245117625227219239138","132484539855842639482281615278990755430","91084610583068807085765739146917762696","325964611958113848557112742679653658410","32810377418042952559312004132516276544","158996660578048398778319337486633319626","266115676673481322223671943969225506183","195279823748529984098975341398306734962","108125708183562296432089142123464721905","230346361445708421057493592911786746403","210815834592956290833471282568598854511","215578510471913616456827611435503739635","109410987532974690305163547015285169672","215525102597053071524691911702249255325","285089423717504197562678829725324904275","194533515942006000079354941602591391022","146265808484144358662494397102214831871","257957075005033943824537900564347715360","201222901048259610950474034792995420505","13582196601229332554038983946126647756","63920062959222075581313928306758730330","7977508964721076778570563388884960898","21504147094284097541678590174042068673","61015623000643770372327914122839669739","203594023515906274076288844326411956818","177395338539459243031850630721058656145","210437896992402480880450247531070908789","65484434721227795840428506566575683707","75959905059366367247512709508833764","104581237962235621860783118979467971070","314927975657919560934777620317018387620","45579621982003412475087610402235507511","324786285915163769520543547154411452890","120341607930997650939096069440375476750","269447398799638328507389104246836327211","92257610095201388953819881554883043963","39267159669395348176306790318881356251","41516016351163515349962957211754120797","117961733633514869159242893481624569272","44827944932748090993047579016258514380","202775890495068603775472914081725681814","189158307364902192198560406334005467521","54878195908181017352654410845212219205","179399546178105068532339370905182198796","234158417323315166796527479965455904594","68124481767486692857289309419655088619","256767746757437810273173197783024210335","21445151495086944347219379209121883442","152793021953604699167546699312269155477","330881963696138850684580986009383152866","6816354076138579603475057761936340163","269047540980081102225914707708125068744","45305459982746280833601095592265324126","62017676319847940805722096241502206883","160955645583718132809768159492526230771","155489987127921599766223943648197304917","269129279886434733163235047211065218937","192422623220467690881925535132718000758","15344032888434487992553771110171443891","160705295112980226453955282223541266215","299559825698827917450181070059309181645","86540194855984973659866980936771484083","30925511399876861469540802245419859844","93112391701870187946953301775099266720","204531659501233147645852639639634974662","247494090199036063289891580891910298786","23818158632179352055336501421013691480","93722438097865937555493833650956507305"],"threshold":0.9},"id":"CVE-2024-54150-ebe120f2","signature_type":"Line","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"tests/test_cjwt.c"},"deprecated":false},{"digest":{"function_hash":"310440325121176508469454315482009813224","length":1619},"id":"CVE-2024-54150-f397fd88","signature_type":"Function","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"tests/test_cjwt.c","function":"test_case"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"79519667416770280848147503233474323469","length":1693},"id":"CVE-2024-54150-fae67594","signature_type":"Function","signature_version":"v1","source":"https://github.com/xmidt-org/cjwt/commit/096ab3e37f73c914b716e7259589179f363265fd","target":{"file":"src/cjwt.c","function":"process_header_json"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}