Uncontrolled Recursion in Nimbus JOSE+JWT - CVE-2025-53864

 

Uncontrolled Recursion in Nimbus JOSE+JWT - CVE-2025-53864

Published: September 26, 2025


Vulnerability identifier: #VU116142
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L]
CVE-ID: CVE-2025-53864
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack via a deeply nested JSON object supplied in a JWT claim set.


Affected software

Nimbus JOSE+JWT
Netezza Appliance
DataPower Operations Dashboard
watsonx Orchestrate Developer Edition
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
UrbanCode Build
DevOps
Maximo Application Suite Ai Service
Rational Performance Tester
IBM Engineering Requirements Management DOORS Next
IBM Event Endpoint Management
DevOps Test Performance
DevOps Test UI
Oracle Data Integrator
Cloudera Observability with IBM
IBM Engineering Lifecycle Optimization - Publishing
Engineering Lifecycle Management - Jazz Foundation
webMethods Managed File Transfer
Guardium Data Protection
IBM Cloud Pak System
Oracle Utilities Application Framework
Communications Unified Assurance
IBM Sterling B2B Integrator
IBM Spectrum Symphony
Oracle Communications Unified Inventory Management
Rational Functional Tester (RFT)
Splunk AppDynamics Database Agent
IBM Sterling File Gateway
RSA Authentication Manager
Event Streams
IBM InfoSphere Information Server
Oracle Essbase
Oracle GoldenGate Big Data and Application Adapters
Oracle WebLogic Server

How to mitigate CVE-2025-53864

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

Nimbus JOSE+JWT - addressed in versions 9.37.4, 10.0.2
Netezza Appliance - update to 1.0.0.1
DataPower Operations Dashboard - update to 1.0.23.2
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Cloud Pak System - update to 2.3.5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
IBM Sterling B2B Integrator - addressed in versions 6.2.0.6, 6.2.1.2, 6.2.2.0
IBM Sterling File Gateway - addressed in versions 6.2.0.6, 6.2.1.2, 6.2.2.0
DevOps - update to 7.1.0.2
IBM Spectrum Symphony - update to 7.3.2 FP3
RSA Authentication Manager - update to 8.9 Patch 1
Maximo Application Suite Ai Service - update to 9.1.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Event Endpoint Management - update to 11.7.0
DevOps Test Performance - update to 11.0.8
Event Streams - update to 12.2.0
DevOps Test UI - update to 11.0.7
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Splunk AppDynamics Database Agent - update to 26.1.0
Cloudera Observability with IBM - update to 3.6.2
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.2.36, 7.0.3.19, 7.1.0.5
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix020, 7.1.0 iFix006
webMethods Managed File Transfer - update to 11.1 Server Fix2
Guardium Data Protection - update to 12.0p50

External References

Related Security Bulletins