Логотип exploitDog
bind:CVE-2025-53864
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-53864

Количество 4

Количество 4

ubuntu логотип

CVE-2025-53864

около 1 месяца назад

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2025-53864

около 1 месяца назад

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2025-53864

около 1 месяца назад

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xwmg-2g98-w7v9

около 1 месяца назад

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-53864

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2025-53864

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-53864

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xwmg-2g98-w7v9

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

CVSS3: 5.8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу