web-token/jwt-rsa15

The RSA1_5 key encryption algorithm for the JWT Framework.

Maintainers

Package info

github.com/web-token/jwt-rsa15

Homepage

pkg:composer/web-token/jwt-rsa15

Transparency log

Statistics

Installs: 332

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

4.3.x-dev 2026-08-29 19:33 UTC

This package is auto-updated.

Last update: 2026-08-30 14:19:18 UTC


README

This repository is a sub repository of the JWT Framework project and is READ ONLY.

Please do not submit any Pull Request here. You should go to the main repository instead.

What Is In This Package?

The RSA1_5 key encryption algorithm (RSAES-PKCS1-v1_5) of RFC 7518, section 4.2.

It is not an experimental algorithm: it is perfectly standard, but its padding is vulnerable to the Bleichenbacher adaptive chosen-ciphertext attack, and RFC 8017 discourages it for new applications. It is shipped apart from the main library so that using it is an explicit and auditable decision. Use RSA-OAEP-256 instead whenever the other party supports it.

The RSASSA-PKCS1-v1_5 signature algorithms (RS256, RS384, RS512) are a different family: they are not affected by this attack and remain in the main library.

Documentation

The official documentation is available as https://web-token.spomky-labs.com/

Licence

This software is release under MIT licence.