CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch...Show more |
2Debian Latchset2Debian Linux JwcryptoJun 17, 2026 Mar 21, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio....Show more |
3Fedoraproject LatchsetRedhat6Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+3 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result...Show more |
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million...Show more |