<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:17:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277201</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277201</link>
      <description>EUVD-2026-277201</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277201</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33204</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33204</link>
      <description>&lt;p&gt;SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33204</guid>
    </item>
    <item>
      <title>GHSA-xw36-67f8-339x — SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw36-67f8-339x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: kelvinmo/simplejwt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used.  
Applications that call `JWE::decrypt()` on attacker-controlled JWEs using PBES2 algorithms are affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;PHP version: `PHP 8.4.11`
SimpleJWT version: `v1.1.0`&lt;/p&gt;
&lt;p&gt;The relevant portion of the vulnerable implementation is shown below ([PBES2.php](https://github.com/kelvinmo/simplejwt/blob/edb7807a240b72c59e72d7dca31add9d16555f9f/src/SimpleJWT/Crypt/KeyManagement/PBES2.php)):&lt;/p&gt;
&lt;p&gt;```PHP
&amp;lt;?php
/* ... SNIP ... */
class PBES2 extends BaseAlgorithm implements KeyEncryptionAlgorithm {
    use AESKeyWrapTrait;&lt;/p&gt;
&lt;p&gt;/** @var array&amp;lt;string, mixed&amp;gt; $alg_params */
    static protected $alg_params = [
        &amp;#39;PBES2-HS256+A128KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha256&amp;#39;],
        &amp;#39;PBES2-HS384+A192KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha384&amp;#39;],
        &amp;#39;PBES2-HS512+A256KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha512&amp;#39;]
    ];&lt;/p&gt;
&lt;p&gt;/** @var truthy-string $hash_alg */
    protected $hash_alg;&lt;/p&gt;
&lt;p&gt;/** @var int $iterations */
    protected $iterations = 4096;
    
    /* ... SNIP ... */&lt;/p&gt;
&lt;p&gt;/**
     * Sets the number of iterations to use in PBKFD2 key generation.
     *
     * @param int $iterations number of iterations
     * @return void
     */
    public function setIterations(int $iterations) {
        $this-&amp;gt;iterations = $iterations;
    }
    
    /* ... SNIP ... */&lt;/p&gt;
&lt;p&gt;/**
     * {@inheritdoc}
     */
    public function decryptKey(string $encrypted_key, KeySet $keys, array $headers, ?string $kid = null): s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: kelvinmo/simplejwt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used.  
Applications that call `JWE::decrypt()` on attacker-controlled JWEs using PBES2 algorithms are affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;PHP version: `PHP 8.4.11`
SimpleJWT version: `v1.1.0`&lt;/p&gt;
&lt;p&gt;The relevant portion of the vulnerable implementation is shown below ([PBES2.php](https://github.com/kelvinmo/simplejwt/blob/edb7807a240b72c59e72d7dca31add9d16555f9f/src/SimpleJWT/Crypt/KeyManagement/PBES2.php)):&lt;/p&gt;
&lt;p&gt;```PHP
&amp;lt;?php
/* ... SNIP ... */
class PBES2 extends BaseAlgorithm implements KeyEncryptionAlgorithm {
    use AESKeyWrapTrait;&lt;/p&gt;
&lt;p&gt;/** @var array&amp;lt;string, mixed&amp;gt; $alg_params */
    static protected $alg_params = [
        &amp;#39;PBES2-HS256+A128KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha256&amp;#39;],
        &amp;#39;PBES2-HS384+A192KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha384&amp;#39;],
        &amp;#39;PBES2-HS512+A256KW&amp;#39; =&amp;gt; [&amp;#39;hash&amp;#39; =&amp;gt; &amp;#39;sha512&amp;#39;]
    ];&lt;/p&gt;
&lt;p&gt;/** @var truthy-string $hash_alg */
    protected $hash_alg;&lt;/p&gt;
&lt;p&gt;/** @var int $iterations */
    protected $iterations = 4096;
    
    /* ... SNIP ... */&lt;/p&gt;
&lt;p&gt;/**
     * Sets the number of iterations to use in PBKFD2 key generation.
     *
     * @param int $iterations number of iterations
     * @return void
     */
    public function setIterations(int $iterations) {
        $this-&amp;gt;iterations = $iterations;
    }
    
    /* ... SNIP ... */&lt;/p&gt;
&lt;p&gt;/**
     * {@inheritdoc}
     */
    public function decryptKey(string $encrypted_key, KeySet $keys, array $headers, ?string $kid = null): s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw36-67f8-339x</guid>
    </item>
  </channel>
</rss>
