NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #416 most downloaded on Packagist
JWT library
Last release 26 days ago
12 Sep 2026
Ships fairly regularly
a new release about every 2 months
Some releases are documented
notes for 15 of 39 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
39 releases · first in 2024
fix(composer): allow brick/math 1.0
fix(composer): allow brick/math 1.0 (#730)
Nothing published for this version
Merge pull request #698 from web-token/fix/jwe-builder-shared-header-…
Merge pull request #698 from web-token/fix/jwe-builder-shared-header-…
One column per month.
JWSBuilder::withEncodedPayload() takes the payload in the form the caller already holds, instead of forcing a decode just so the builder can encode it
JWSBuilder::withEncodedPayload() takes the payload in the form the caller
already holds, instead of forcing a decode just so the builder can encode it
back. GNAP request signing is the case that asked for it: the payload there is
the Base64Url encoded SHA-256 hash of the request body.
Handing such a string to withPayload() encodes it twice and silently yields a
token whose payload nobody expects. The new method states the intent and checks
it: the value goes through Base64UrlSafe::decodeNoPadding(), so padding, the
Base64 alphabet, impossible lengths and non-canonical trailing bits are all
rejected. That is the strictness CompactSerializer already applies when
loading a token, so the builder cannot emit what the library itself refuses to
read back.
An encoded payload contradicts b64: false, which removes the encoding
altogether; the combination is rejected whichever order the two are set in.
The method, its name and the use case come from Aaron Parecki in #329.
Closes #329
Co-authored-by: Aaron Parecki aaron@parecki.com
The compact JWS and JWE serializers split the whole input on every "." before checking the segment count, so a delimiter-heavy string was first expand
The compact JWS and JWE serializers split the whole input on every "."
before checking the segment count, so a delimiter-heavy string was first
expanded into one array entry per delimiter. That costs about 25 times
the size of the input in memory: a 2 MB token allocates ~48 MB before it
is rejected as malformed.
The split is now bounded to one more segment than a valid token has,
which is enough to detect and reject longer input while keeping the
allocation proportional to the token itself. The accepted and rejected
inputs are unchanged.
Reported by Team Atlanta.
The compact JWS and JWE serializers split the whole input on every "." before checking the segment count, so a delimiter-heavy string was first expand
The compact JWS and JWE serializers split the whole input on every "."
before checking the segment count, so a delimiter-heavy string was first
expanded into one array entry per delimiter. That costs about 25 times
the size of the input in memory: a 2 MB token allocates ~48 MB before it
is rejected as malformed.
The split is now bounded to one more segment than a valid token has,
which is enough to detect and reject longer input while keeping the
allocation proportional to the token itself. The accepted and rejected
inputs are unchanged.
Reported by Team Atlanta.
Merge branch '4.0.x' into 4.1.x
Merge branch '4.0.x' into 4.1.x
Mise à jour de la contrainte de version de brick/math pour inclure le…
Mise à jour de la contrainte de version de brick/math pour inclure le…
Fix PHP 8.5 deprecation
Fix PHP 8.5 deprecation (#648)
Fix PHP 8.5 deprecation
Fix PHP 8.5 deprecation (#648)
Fix PHP 8.5 deprecation
Fix PHP 8.5 deprecation (#648)
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Refactor command help text definitions for Symfony Console compatibil…
Refactor command help text definitions for Symfony Console compatibil…
Nothing published for this version
3.4.x: Update signature tests for the protected-header "alg" requirement (#651) Merge commit from fork Merge commit from fork Merge commit from fork M
psr/cache v2 (#620)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
JWSVerifier::getAlgorithm() merged the protected and unprotected headers with [...$protected, ...$unprotected]; with duplicate keys PHP keeps the LAST
JWSVerifier::getAlgorithm() merged the protected and unprotected headers
with [...$protected, ...$unprotected]; with duplicate keys PHP keeps the
LAST value, so the attacker-controlled unprotected header could override
the integrity-protected "alg". Combined with HeaderCheckerManager (which
validates "alg" from the protected header), this is a TOCTOU
algorithm-confusion / downgrade vector (e.g. forcing HS256 against an RSA
public key, or HS512 -> HS256), and "alg" placed only in the unprotected
header bypassed the duplicate-parameter check entirely.
Per RFC 7515 §4.1.1 "alg" MUST be integrity protected. getAlgorithm() now
reads "alg" exclusively from the protected header and rejects a JWS whose
"alg" is absent from (or present only outside) the protected header.
Co-authored-by: Claude Opus 4.8 (1M context) noreply@anthropic.com
Add sodium support for Base64 URL safe encoding/decoding
Add sodium support for Base64 URL safe encoding/decoding (#644)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →