Improper handling of highly compressed data in jwcrypto - CVE-2026-39373
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the deserialize function when processing crafted JWE tokens with ZIP compression. A remote attacker can send a specially crafted JWE token to cause a denial of service.
Memory-constrained systems are more likely to be affected.
Affected software
Anolis OS
openEuler
python-jwcrypto
python-jwcrypto-help
python3-jwcrypto
python3-jwcrypto-doc
How to mitigate CVE-2026-39373
python-jwcrypto - update to 1.5.0-4
python-jwcrypto-help - update to 1.5.0-4
python3-jwcrypto - update to 1.5.0-4
python3-jwcrypto - update to 1.5.7-1
python3-jwcrypto-doc - update to 1.5.7-1