rpm package
opensuse/python-jwcrypto&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/python-jwcrypto&distro=openSUSE%20Tumbleweed
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-84185 | Med | 5.9 | < 1.6.0-1.1 | 1.6.0-1.1 | Sep 3, 2026 | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correct | |
| CVE-2026-80179 | Med | 5.9 | < 1.6.0-1.1 | 1.6.0-1.1 | Aug 28, 2026 | A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue res | |
| CVE-2026-39373 | Med | 5.3 | < 1.5.7-2.1 | 1.5.7-2.1 | Apr 7, 2026 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but do | |
| CVE-2024-28102 | Med | 6.8 | < 1.6.0-1.1 | 1.6.0-1.1 | Mar 21, 2024 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot | |
| CVE-2022-3102 | med | — | < 1.4.2-1.1 | 1.4.2-1.1 | Sep 21, 2022 | The JWT code can auto-detect the type of token being provided, and this can lead the application to incorrect conclusions about the trustworthiness of the token. Quoting the private disclosure we received : "Under certain circumstances, it is possible to substitute a [..] signed |
- affected < 1.6.0-1.1fixed 1.6.0-1.1
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correct
- affected < 1.6.0-1.1fixed 1.6.0-1.1
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue res
- affected < 1.5.7-2.1fixed 1.5.7-2.1
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but do
- affected < 1.6.0-1.1fixed 1.6.0-1.1
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot
- affected < 1.4.2-1.1fixed 1.4.2-1.1
The JWT code can auto-detect the type of token being provided, and this can lead the application to incorrect conclusions about the trustworthiness of the token. Quoting the private disclosure we received : "Under certain circumstances, it is possible to substitute a [..] signed