← Back

CVE-2024-29370

nvd nist
Published: Dec 17, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.

Affected (1)

Python Jose
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.3.0

References (1)

Source: cve@mitre.org
ExploitIssue TrackingPatch

Timeline

No history available yet.