Improper handling of highly compressed data in jwcrypto - CVE-2026-39373
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the deserialize function when processing crafted JWE tokens with ZIP compression. A remote attacker can send a specially crafted JWE token to cause a denial of service.
Memory-constrained systems are more likely to be affected.
Affected software
openEuler
Anolis OS
python-jwcrypto
python3-jwcrypto
python-jwcrypto-help
python3-jwcrypto-doc
How to mitigate CVE-2026-39373
python-jwcrypto - addressed in versions 1.4.2-4, 1.5.0-4
python3-jwcrypto - addressed in versions 1.4.2-4, 1.5.0-4
python-jwcrypto-help - update to 1.5.0-4
python3-jwcrypto - update to 1.5.7-1
python3-jwcrypto-doc - update to 1.5.7-1
External References
Related Security Bulletins
- Denial of service in jwcrypto
- openEuler 24.03 LTS SP1 update for python-jwcrypto
- openEuler 24.03 LTS update for python-jwcrypto
- openEuler 24.03 LTS SP3 update for python-jwcrypto
- openEuler 24.03 LTS SP2 update for python-jwcrypto
- Anolis OS update for python-jwcrypto
- openEuler 22.03 LTS SP4 update for python-jwcrypto