VYPR

rpm package

opensuse/python-jwcrypto&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-jwcrypto&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-84185MedSep 3, 2026
    affected < 1.6.0-1.1fixed 1.6.0-1.1

    A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correct

  • CVE-2026-80179MedAug 28, 2026
    affected < 1.6.0-1.1fixed 1.6.0-1.1

    A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue res

  • CVE-2026-39373MedApr 7, 2026
    affected < 1.5.7-2.1fixed 1.5.7-2.1

    JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but do

  • CVE-2024-28102MedMar 21, 2024
    affected < 1.6.0-1.1fixed 1.6.0-1.1

    JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot

  • CVE-2022-3102medSep 21, 2022
    affected < 1.4.2-1.1fixed 1.4.2-1.1

    The JWT code can auto-detect the type of token being provided, and this can lead the application to incorrect conclusions about the trustworthiness of the token. Quoting the private disclosure we received : "Under certain circumstances, it is possible to substitute a [..] signed