Логотип exploitDog
bind:"GHSA-pq5p-34cr-23v9" OR bind:"CVE-2025-61920"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-pq5p-34cr-23v9" OR bind:"CVE-2025-61920"

Количество 8

Количество 8

github логотип

GHSA-pq5p-34cr-23v9

6 месяцев назад

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-61920

6 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-61920

6 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-61920

6 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-61920

6 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3754-1

6 месяцев назад

Security update for python-Authlib

EPSS: Низкий
redos логотип

ROS-20260122-73-0007

2 месяца назад

Уязвимость python-authlib

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-03457

6 месяцев назад

Уязвимость реализации JOSE библиотеки Authlib для серверов OAuth и OpenID Connect, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pq5p-34cr-23v9

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3754-1

Security update for python-Authlib

0%
Низкий
6 месяцев назад
redos логотип
ROS-20260122-73-0007

Уязвимость python-authlib

CVSS3: 7.5
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-03457

Уязвимость реализации JOSE библиотеки Authlib для серверов OAuth и OpenID Connect, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу