Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-39373

4 месяца назад

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-39373

4 месяца назад

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39373

4 месяца назад

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-39373

4 месяца назад

JWCrypto implements JWK, JWS, and JWE specifications using python-cryp ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20644-1

3 месяца назад

Security update for python-jwcrypto

EPSS: Низкий
rocky логотип

RLSA-2026:19197

2 месяца назад

Low: python-jwcrypto security update

EPSS: Низкий
rocky логотип

RLSA-2026:19042

2 месяца назад

Low: python-jwcrypto security update

EPSS: Низкий
github логотип

GHSA-fjrm-76x2-c4q4

4 месяца назад

JWCrypto: JWE ZIP decompression bomb

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19197

около 2 месяцев назад

ELSA-2026-19197: python-jwcrypto security update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19042

25 дней назад

ELSA-2026-19042: python-jwcrypto security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2026-07340

4 месяца назад

Уязвимость JavaScript-библиотеки для криптографии Jwcrypto, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260506-73-0048

3 месяца назад

Уязвимость python2-jwcrypto

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260506-73-0047

3 месяца назад

Уязвимость python-jwcrypto

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-39373

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 5.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39373

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39373

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS3: 5.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-39373

JWCrypto implements JWK, JWS, and JWE specifications using python-cryp ...

CVSS3: 5.3
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20644-1

Security update for python-jwcrypto

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:19197

Low: python-jwcrypto security update

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:19042

Low: python-jwcrypto security update

0%
Низкий
2 месяца назад
github логотип
GHSA-fjrm-76x2-c4q4

JWCrypto: JWE ZIP decompression bomb

CVSS3: 5.3
0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19197

ELSA-2026-19197: python-jwcrypto security update (LOW)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-19042

ELSA-2026-19042: python-jwcrypto security update (LOW)

25 дней назад
fstec логотип
BDU:2026-07340

Уязвимость JavaScript-библиотеки для криптографии Jwcrypto, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
4 месяца назад
redos логотип
ROS-20260506-73-0048

Уязвимость python2-jwcrypto

CVSS3: 5.3
0%
Низкий
3 месяца назад
redos логотип
ROS-20260506-73-0047

Уязвимость python-jwcrypto

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу