Allocation of Resources Without Limits or Throttling in jwcrypto - CVE-2026-80179
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in JWE.deserialize() compact JWE parsing fallback when parsing attacker-controlled malformed non-JSON token text with many period delimiters. A remote attacker can send a specially crafted JWE string to cause a denial of service.
Exploitation requires the application to pass untrusted JWE input to the deserializer before authentication succeeds.