Shorstop LogoshorstopCryptographic Inventory for a Post-Quantum World

auth0/java-jwt

Branch
master
Commit
4674f5a
Committed
2026-09-07
Scanned
2026-09-07, 15:56
text scan · 49 of 134 filesWhat was scanned

Scanner Shorstop 0.2.0 · text scan

Coverage 49 source files scanned of 134 in the repository; 43 skipped in test, vendored and build directories. What is excluded

Findings are starting points for investigation, not a security assessment. How scanning works

Total Cryptographic Assets

87

Files Impacted

8

Quantum-Vulnerable Assets

32%

28 of 87

Deprecated after 2030, disallowed after 2035 — NIST IR 8547

Quantum-Safe Assets

15%

13 of 87

NIST-approved: FIPS 203 ML-KEM, 204 ML-DSA, 205 SLH-DSA

Quantum Readiness

Categories:

Post-Quantum Cryptography: NIST-approved PQC (Kyber, Dilithium, SPHINCS+)
Quantum-Safe Classical: Symmetric/hash with 256+ bit security (AES-256, SHA-256)
Quantum-Resistant Uncertain: Needs validation (AES-128, XMSS, some hash functions)
Quantum-Vulnerable: Broken by Shor's algorithm (RSA, ECDSA, DH)
Classically Weak: Broken TODAY (MD5, SHA-1, DES, RC4)
Unknown: Generic names, unidentifiable algorithms

By Algorithm Type

Algorithm Types:

Block Cipher: Symmetric encryption (AES, DES, ChaCha20)
Hash Function: One-way digest (SHA-256, MD5, BLAKE2)
Digital Signature: Asymmetric signing (RSA, ECDSA, Dilithium)
Message Authentication: MAC codes (HMAC, CMAC, Poly1305)
Key Derivation: KDF functions (PBKDF2, Argon2, HKDF)
Public Key Encryption: Asymmetric encryption (RSA, Kyber)
Public Key Cipher: Public key cryptography (RSA, ElGamal)
Key Exchange: Key agreement (ECDH, X25519, Kyber-KEM)
Authenticated Encryption: Combined encryption+MAC (AES-GCM, ChaCha20-Poly1305)
Extendable-Output Function: Variable-length output (SHAKE128, SHAKE256)
Other: Miscellaneous or unclassified algorithms

By Purpose

Purpose Types:

Encryption: Protect data confidentiality
Decryption: Recover original data
Digital Signing: Prove authenticity and integrity
Signature Verification: Validate digital signatures
Key Generation: Create cryptographic keys
Key Agreement: Establish shared secrets
Hashing: Generate message digests
Other: Miscellaneous or unclassified operations

Cryptographic Assets

Export

Cryptographic Bill of Materials (CycloneDX)

NamePrimitiveFunctionsFile:LineRisk
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:133
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:135
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:139
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:143
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:147
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:151
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:160
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:163
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:173
Quantum vulnerable
RSA-PSS-signothersignlib/src/main/java/com/auth0/jwt/algorithms/Algorithm.java:175
Quantum vulnerable
Page 1 of 9
Shorstop reports automated source-code findings for investigation. Matches can include example code, commented-out code and non-production usage, and should be reviewed in context. Test directories, vendored dependencies and build output are not scanned. A Shorstop scan is not a substitute for a formal security assessment. How scanning worksFound an incorrect result? Report it.