pawlos
## Description Fuzzing jose-jwt 5.2.0 with AFL++ and SharpFuzz found **3 unique crashes** triggered by malformed JWT tokens. The library does not validate token structure and header field types before processing, leading to `NullReferenceException` and `InvalidCastException`. ### Crash 1 - NullRef in `JWT.DecodeBytes` (2 bytes) ``` System.NullReferenceException: Object reference not set to an instance of an object. at Jose.JWT.DecodeBytes(Iterator parts, Object key, ...) at Jose.JWT.Decode(String token, Object key, ...) ``` Input: `..` (two dots). The token is split into parts but the header part is empty, resulting in a null dereference. ### Crash 2 - InvalidCast in `JWT.DecodeBytes` (43 bytes) ``` System.InvalidCastException: Unable to cast object of type 'System.Int64' to type 'System.String'. at Jose.JWT.DecodeBytes(Iterator parts, Object key, ...) at Jose.JWT.Decode(String token, Object key, ...) ``` Input: `eyJhbGciOjJ9.eyKhbGciOiJGciOjJ9.eyKhbGciOiJ` - the header decodes to `{"alg":2}` (numeric value instead of string). The code casts the `alg` field to `string` without checking the type. ### Crash 3 - InvalidCast in `JWE.Decrypt` (23 bytes) ``` System.InvalidCastException: Unable to cast object of type 'System.Int64' to type 'System.String'. at Jose.JWE.Decrypt(String jwe, Object key, ...) at Jose.JWT.DecodeBytes(Iterator parts, Object key, ...) ``` Input: `eyJhbGciOjJ9..SH9typ9..` - same type confusion in the JWE decryption path. A 5-part token with a numeric `alg` header triggers the cast failure. ## Reproduction ```csharp using Jose; // Crash 1 - NullRef (2 bytes!) try { JWT.Decode("..", JwsAlgorithm.none); } catch (Exception ex) { Console.WriteLine($"crash_1: {ex.GetType().Name}"); } // Crash 2 - InvalidCast in JWS path (header: {"alg":2}) try { JWT.Decode("eyJhbGciOjJ9.eyKhbGciOiJGciOjJ9.eyKhbGciOiJ", JwsAlgorithm.none); } catch (Exception ex) { Console.WriteLine($"crash_2: {ex.GetType().Name}"); } // Crash 3 - InvalidCast in JWE path (header: {"alg":2}) try { JWT.Decode("eyJhbGciOjJ9..SH9typ9..", JwsAlgorithm.none); } catch (Exception ex) { Console.WriteLine($"crash_3: {ex.GetType().Name}"); } ``` ## Expected Behavior `JWT.Decode` and `JWT.Headers` should throw `JoseException` for malformed tokens, not `NullReferenceException` or `InvalidCastException`. Specifically: - Empty/missing parts after splitting on `.` should be rejected early - Header field types should be validated (e.g. `alg` must be a string, not a number) ## Additional Context - **jose-jwt version**: 5.2.0 (latest on NuGet) - **.NET version**: .NET 10.0, Linux x64 - The InvalidCastException bugs occur because header fields deserialized from JSON are not type-checked before casting (e.g. `alg` as a number instead of string) - Found via coverage-guided fuzzing with [AFL++](https://github.com/AFLplusplus/AFLplusplus) and [SharpFuzz](https://github.com/Metalnem/sharpfuzz)