<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:35:12.976291+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:19042</id>
    <title>ALSA-2026:19042 — Low: python-jwcrypto security update</title>
    <updated>2026-10-04T11:35:13.411775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3-jwcrypto</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:19042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07340</id>
    <title>bdu:2026-07340</title>
    <updated>2026-10-04T11:35:13.411856+00:00</updated>
    <content>bdu:2026-07340</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-gimme-aws-creds-cve-2026-39373</id>
    <title>BREW-gimme-aws-creds-CVE-2026-39373 — JWCrypto: JWE ZIP decompression bomb</title>
    <updated>2026-10-04T11:35:13.411874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: gimme-aws-creds</p>
<p>### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.</p>
<p>Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.</p>
<p>NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.</p>
<p>NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the "details" section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the "suggested fix" is actually no solution at all, as it was using the very call that he claimed was causing "arbitrary" memory exhaustion and wrapping it around an "if" ... the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-gimme-aws-creds-cve-2026-39373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T11:35:13.411924+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281171</id>
    <title>EUVD-2026-281171</title>
    <updated>2026-10-04T11:35:13.411940+00:00</updated>
    <content>EUVD-2026-281171</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39373</id>
    <title>fkie_cve-2026-39373</title>
    <updated>2026-10-04T11:35:13.411952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fjrm-76x2-c4q4</id>
    <title>GHSA-fjrm-76x2-c4q4 — JWCrypto: JWE ZIP decompression bomb</title>
    <updated>2026-10-04T11:35:13.411975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jwcrypto</p>
<p>### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.</p>
<p>Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.</p>
<p>NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.</p>
<p>NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the "details" section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the "suggested fix" is actually no solution at all, as it was using the very call that he claimed was causing "arbitrary" memory exhaustion and wrapping it around an "if" ... the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fjrm-76x2-c4q4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1923</id>
    <title>OESA-2026-1923 — python-jwcrypto security update</title>
    <updated>2026-10-04T11:35:13.412018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: python-jwcrypto</p>
<p>Implements JWK, JWS, JWE specifications with python-cryptography

Security Fix(es):</p>
<p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.(CVE-2026-39373)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10576-1</id>
    <title>openSUSE-SU-2026:10576-1 — python311-jwcrypto-1.5.7-2.1 on GA media</title>
    <updated>2026-10-04T11:35:13.412042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-jwcrypto-1.5.7-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10576-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-70</id>
    <title>PYSEC-2026-70</title>
    <updated>2026-10-04T11:35:13.412059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jwcrypto</p>
<p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-70"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13508</id>
    <title>RHSA-2026:13508 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
    <updated>2026-10-04T11:35:13.412079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21425-1</id>
    <title>SUSE-SU-2026:21425-1 — Security update for python-jwcrypto</title>
    <updated>2026-10-04T11:35:13.412120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-jwcrypto</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21425-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39373</id>
    <title>UBUNTU-CVE-2026-39373</title>
    <updated>2026-10-04T11:35:13.412137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto</p>
<p>JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1610</id>
    <title>WID-SEC-W-2026-1610 — Red Hat Enterprise Linux (JWCrypto und python-markdown): Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T11:35:13.412167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1610"/>
  </entry>
</feed>
