JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Latchset Latchset jwcrypto |
|
| CPEs | cpe:2.3:a:latchset:jwcrypto:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Latchset Latchset jwcrypto |
Mon, 09 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 19 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-03-06T21:09:58.064Z
Updated: 2024-09-09T13:06:44.240Z
Reserved: 2024-03-04T14:19:14.058Z
Link: CVE-2024-28102
Updated: 2024-09-09T13:06:44.240Z
Status : Analyzed
Published: 2024-03-21T02:52:23.513
Modified: 2025-12-22T16:09:47.343
Link: CVE-2024-28102