CVE-2025-54887 affects the Ruby jwe library, an implementation of RFC 7516 JSON Web Encryption. In jwe versions 1.1.0 and earlier, authentication tags on encrypted JWEs can be brute forced. According to the provided advisory, this can allow attackers to modify JWEs so they decrypt to arbitrary values, infer plaintext by observing parsing differences during decryption, and recover the AES-GCM GHASH internal key. The issue affects users even when they are not explicitly using an AES-GCM encryption algorithm for their JWEs, indicating the vulnerable verification/decryption logic is broadly reachable within the library. The flaw is fixed in version 1.1.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
jwe library for processing untrusted JWEs, limiting acceptance of externally supplied encrypted JWEs, and isolating services that decrypt them. Monitor for anomalous JWE validation/decryption failures and suspicious token manipulation attempts. However, these are only temporary measures; the authoritative fix is upgrading to 1.1.1+ and rotating encryption keys because previously used keys may already be compromised.Patch, then assume compromise.
jwe gem to version 1.1.1 or later. Because the advisory states the AES-GCM GHASH key may have been exposed, remediation is not limited to patching: affected deployments should also rotate the encryption keys used with the library after upgrading. Any encrypted JWEs or trust decisions relying on previously exposed keys should be treated as potentially compromised.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-54887, a vulnerability in the 'ruby-jwe' gem (version <= 1.1.0) that allows brute-forcing of the authentication tag in encrypted JSON Web Encryption (JWE) tokens. The repository contains two main Ruby scripts: - 'exploit.rb': Demonstrates brute-forcing the single-byte authentication tag of a JWE token, allowing decryption of the protected data if the correct tag is found. - 'forge-jwe.rb': Shows how to modify the ciphertext of a JWE token (e.g., changing a username from 'macie' to 'admin') and then brute-force the authentication tag to successfully decrypt the forged token, demonstrating the ability to craft arbitrary tokens. Both scripts use the 'jwe' gem and require Ruby. The exploit targets applications using vulnerable versions of 'ruby-jwe' with the 'dir' algorithm and 'A256GCM' encryption. No network endpoints or external services are targeted; the exploit operates locally on crafted tokens. The repository is structured with a README, license, and the two exploit scripts, and serves as a clear demonstration of the vulnerability's impact.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.