MEDIUM5.3PyPI
GHSA-cw2r-4p82-qv79· CVE-2023-6681, PYSEC-2024-104DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value
Modified: 11/12/2024
package
pkg:pypi/jwcrypto
DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value
Modified: 11/12/2024
JWCrypto: JWE ZIP decompression bomb
Modified: 9/10/2026
jwcrypto token substitution can lead to authentication bypass
Modified: 7/7/2026
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
Modified: 9/10/2026
jwcrypto lacks the Random Filling protection mechanism
Modified: 11/19/2024
Modified: 6/10/2026
Modified: 6/10/2026
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
Modified: 7/7/2026
Modified: 5/21/2026
jwcrypto token substitution can lead to authentication bypass
Modified: 7/7/2026