Количество 13
Количество 13
CVE-2026-39373
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.
CVE-2026-39373
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.
CVE-2026-39373
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.
CVE-2026-39373
JWCrypto implements JWK, JWS, and JWE specifications using python-cryp ...
openSUSE-SU-2026:20644-1
Security update for python-jwcrypto
RLSA-2026:19197
Low: python-jwcrypto security update
RLSA-2026:19042
Low: python-jwcrypto security update
GHSA-fjrm-76x2-c4q4
JWCrypto: JWE ZIP decompression bomb
ELSA-2026-19197
ELSA-2026-19197: python-jwcrypto security update (LOW)
ELSA-2026-19042
ELSA-2026-19042: python-jwcrypto security update (LOW)
BDU:2026-07340
Уязвимость JavaScript-библиотеки для криптографии Jwcrypto, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260506-73-0048
Уязвимость python2-jwcrypto
ROS-20260506-73-0047
Уязвимость python-jwcrypto
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39373 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-39373 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-39373 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-39373 JWCrypto implements JWK, JWS, and JWE specifications using python-cryp ... | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20644-1 Security update for python-jwcrypto | 0% Низкий | 3 месяца назад | ||
RLSA-2026:19197 Low: python-jwcrypto security update | 0% Низкий | 2 месяца назад | ||
RLSA-2026:19042 Low: python-jwcrypto security update | 0% Низкий | 2 месяца назад | ||
GHSA-fjrm-76x2-c4q4 JWCrypto: JWE ZIP decompression bomb | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
ELSA-2026-19197 ELSA-2026-19197: python-jwcrypto security update (LOW) | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-19042 ELSA-2026-19042: python-jwcrypto security update (LOW) | 0% Низкий | 25 дней назад | ||
BDU:2026-07340 Уязвимость JavaScript-библиотеки для криптографии Jwcrypto, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
ROS-20260506-73-0048 Уязвимость python2-jwcrypto | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
ROS-20260506-73-0047 Уязвимость python-jwcrypto | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу