Логотип exploitDog
bind:CVE-2025-61920
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-61920

Количество 6

Количество 6

ubuntu логотип

CVE-2025-61920

4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-61920

4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-61920

4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3754-1

4 месяца назад

Security update for python-Authlib

EPSS: Низкий
redos логотип

ROS-20260122-73-0007

18 дней назад

Уязвимость python-authlib

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pq5p-34cr-23v9

4 месяца назад

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:3754-1

Security update for python-Authlib

0%
Низкий
4 месяца назад
redos логотип
ROS-20260122-73-0007

Уязвимость python-authlib

CVSS3: 7.5
0%
Низкий
18 дней назад
github логотип
GHSA-pq5p-34cr-23v9

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

CVSS3: 7.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу