<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:58:21.573121+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277201</id>
    <title>EUVD-2026-277201</title>
    <updated>2026-10-09T08:58:21.623928+00:00</updated>
    <content>EUVD-2026-277201</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33204</id>
    <title>fkie_cve-2026-33204</title>
    <updated>2026-10-09T08:58:21.623968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xw36-67f8-339x</id>
    <title>GHSA-xw36-67f8-339x — SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering</title>
    <updated>2026-10-09T08:58:21.624003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: kelvinmo/simplejwt</p>
<p>## Summary</p>
<p>An unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used.  
Applications that call `JWE::decrypt()` on attacker-controlled JWEs using PBES2 algorithms are affected.</p>
<p>## Details</p>
<p>PHP version: `PHP 8.4.11`
SimpleJWT version: `v1.1.0`</p>
<p>The relevant portion of the vulnerable implementation is shown below ([PBES2.php](https://github.com/kelvinmo/simplejwt/blob/edb7807a240b72c59e72d7dca31add9d16555f9f/src/SimpleJWT/Crypt/KeyManagement/PBES2.php)):</p>
<p>```PHP
&lt;?php
/* ... SNIP ... */
class PBES2 extends BaseAlgorithm implements KeyEncryptionAlgorithm {
    use AESKeyWrapTrait;</p>
<p>/** @var array&lt;string, mixed&gt; $alg_params */
    static protected $alg_params = [
        'PBES2-HS256+A128KW' =&gt; ['hash' =&gt; 'sha256'],
        'PBES2-HS384+A192KW' =&gt; ['hash' =&gt; 'sha384'],
        'PBES2-HS512+A256KW' =&gt; ['hash' =&gt; 'sha512']
    ];</p>
<p>/** @var truthy-string $hash_alg */
    protected $hash_alg;</p>
<p>/** @var int $iterations */
    protected $iterations = 4096;
    
    /* ... SNIP ... */</p>
<p>/**
     * Sets the number of iterations to use in PBKFD2 key generation.
     *
     * @param int $iterations number of iterations
     * @return void
     */
    public function setIterations(int $iterations) {
        $this-&gt;iterations = $iterations;
    }
    
    /* ... SNIP ... */</p>
<p>/**
     * {@inheritdoc}
     */
    public function decryptKey(string $encrypted_key, KeySet $keys, array $headers, ?string $kid = null): s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xw36-67f8-339x"/>
  </entry>
</feed>
