CVE-2026-89086
CRITICAL
NVD
CVSS Score
9.1
Severity
CRITICAL
Published
Sep 10, 2026
Vendor
unknown
Description
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.