The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
{ "binaries": [ { "binary_version": "1.7.2-1", "binary_name": "ruby-json-jwt" } ] }
{ "binaries": [ { "binary_version": "1.11.0-1", "binary_name": "ruby-json-jwt" } ] }
{ "binaries": [ { "binary_version": "1.13.0-1ubuntu0.1", "binary_name": "ruby-json-jwt" } ] }
{ "binaries": [ { "binary_version": "1.14.0-2", "binary_name": "ruby-json-jwt" } ] }
{ "binaries": [ { "binary_version": "1.16.7-1", "binary_name": "ruby-json-jwt" } ] }