Description
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3883-1 | python-jwcrypto security update |
EUVD |
EUVD-2024-0946 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length. |
Github GHSA |
GHSA-j857-7rvv-vj97 | JWCrypto vulnerable to JWT bomb Attack in `deserialize` function |
References
History
Mon, 22 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Latchset Latchset jwcrypto |
|
| CPEs | cpe:2.3:a:latchset:jwcrypto:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Latchset Latchset jwcrypto |
Mon, 09 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 19 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-09T13:06:44.240Z
Reserved: 2024-03-04T14:19:14.058Z
Link: CVE-2024-28102
Updated: 2024-09-09T13:06:44.240Z
Status : Analyzed
Published: 2024-03-21T02:52:23.513
Modified: 2025-12-22T16:09:47.343
Link: CVE-2024-28102
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA