<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:42:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19042 — Low: python-jwcrypto security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19042</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-jwcrypto&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-jwcrypto&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19042</guid>
    </item>
    <item>
      <title>bdu:2026-07340</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07340</link>
      <description>bdu:2026-07340</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07340</guid>
    </item>
    <item>
      <title>BREW-gimme-aws-creds-CVE-2026-39373 — JWCrypto: JWE ZIP decompression bomb</title>
      <link>https://cve.radiocsirt.org/vuln/brew-gimme-aws-creds-cve-2026-39373</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gimme-aws-creds&lt;/p&gt;
&lt;p&gt;### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.&lt;/p&gt;
&lt;p&gt;Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.&lt;/p&gt;
&lt;p&gt;NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.&lt;/p&gt;
&lt;p&gt;NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the &amp;#34;details&amp;#34; section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the &amp;#34;suggested fix&amp;#34; is actually no solution at all, as it was using the very call that he claimed was causing &amp;#34;arbitrary&amp;#34; memory exhaustion and wrapping it around an &amp;#34;if&amp;#34; ... the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gimme-aws-creds&lt;/p&gt;
&lt;p&gt;### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.&lt;/p&gt;
&lt;p&gt;Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.&lt;/p&gt;
&lt;p&gt;NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.&lt;/p&gt;
&lt;p&gt;NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the &amp;#34;details&amp;#34; section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the &amp;#34;suggested fix&amp;#34; is actually no solution at all, as it was using the very call that he claimed was causing &amp;#34;arbitrary&amp;#34; memory exhaustion and wrapping it around an &amp;#34;if&amp;#34; ... the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-gimme-aws-creds-cve-2026-39373</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>EUVD-2026-281171</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281171</link>
      <description>EUVD-2026-281171</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281171</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39373</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39373</link>
      <description>&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39373</guid>
    </item>
    <item>
      <title>GHSA-fjrm-76x2-c4q4 — JWCrypto: JWE ZIP decompression bomb</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjrm-76x2-c4q4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.&lt;/p&gt;
&lt;p&gt;Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.&lt;/p&gt;
&lt;p&gt;NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.&lt;/p&gt;
&lt;p&gt;NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the &amp;#34;details&amp;#34; section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the &amp;#34;suggested fix&amp;#34; is actually no solution at all, as it was using the very call that he claimed was causing &amp;#34;arbitrary&amp;#34; memory exhaustion and wrapping it around an &amp;#34;if&amp;#34; ... the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can craft a JWE token under the 250KB input limit that decompresses to very large data that may exceed small devices memory availability, causing Denial of Service via memory exhaustion.&lt;/p&gt;
&lt;p&gt;Although this is technically not unbounded I do recognize that it may be too much for devices and is something that could be surprising to developers, and we can do better than that.&lt;/p&gt;
&lt;p&gt;NOTE: the original report was sloppy (probably AI slop) and claimed arbitrary memory consumption, but simple testing showed that while 100MB could be decompressed a 1GB output was denied because the token exceeded the 250K compressed serialization.&lt;/p&gt;
&lt;p&gt;NOTE WELL: The proposed solution was also sloppy, proposing to first decompress the data completely in memory (therefore causing the memory exhaustion) and then checking how much memory was already used to deny the operation. I _intentionally_ left the &amp;#34;details&amp;#34; section untouched to show how bad AI slop is and how _uncritical_ the submitter was, even as it was obvious the &amp;#34;suggested fix&amp;#34; is actually no solution at all, as it was using the very call that he claimed was causing &amp;#34;arbitrary&amp;#34; memory exhaustion and wrapping it around an &amp;#34;if&amp;#34; ... the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjrm-76x2-c4q4</guid>
    </item>
    <item>
      <title>OESA-2026-1923 — python-jwcrypto security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1923</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-jwcrypto&lt;/p&gt;
&lt;p&gt;Implements JWK, JWS, JWE specifications with python-cryptography&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.(CVE-2026-39373)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-jwcrypto&lt;/p&gt;
&lt;p&gt;Implements JWK, JWS, JWE specifications with python-cryptography&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.(CVE-2026-39373)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1923</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10576-1 — python311-jwcrypto-1.5.7-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10576-1</link>
      <description>&lt;p&gt;python311-jwcrypto-1.5.7-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-jwcrypto-1.5.7-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10576-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-70</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-70</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-70</guid>
    </item>
    <item>
      <title>RHSA-2026:13508 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13508</link>
      <description>&lt;p&gt;Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Django: Django: Denial of Service via crafted request with duplicate headers python-markdown: denial of service via malformed HTML-like sequences aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID net/url: Incorrect parsing of IPv6 host literals in net/url minimatch: minimatch: Denial of Service via specially crafted glob patterns pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13508</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21425-1 — Security update for python-jwcrypto</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21425-1</link>
      <description>&lt;p&gt;Security update for python-jwcrypto&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-jwcrypto&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21425-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-39373</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39373</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-jwcrypto, Ubuntu:18.04:LTS: python-jwcrypto, Ubuntu:20.04:LTS: python-jwcrypto, Ubuntu:22.04:LTS: python-jwcrypto, Ubuntu:24.04:LTS: python-jwcrypto, Ubuntu:25.10: python-jwcrypto, Ubuntu:26.04:LTS: python-jwcrypto&lt;/p&gt;
&lt;p&gt;JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102  limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39373</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1610 — Red Hat Enterprise Linux (JWCrypto und python-markdown): Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1610</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1610</guid>
    </item>
  </channel>
</rss>
