Connect2id

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-53864

    com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

    Last Modified: Apr 15, 2026
    Published: Jul 11, 2025

    CVE-2023-52428

    nimbus-jose-jwt: large JWE p2c header value causes Denial of Service

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2024

    CVE-2019-17195

    nimbus-jose-jwt: Uncaught exceptions while parsing a JWT

    Last Modified: Nov 21, 2024
    Published: Oct 15, 2019

    CVE-2017-12972

    In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different plaintext is obtained for the same HMAC.

    Last Modified: Apr 20, 2025
    Published: Aug 20, 2017

    CVE-2017-12973

    Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.

    Last Modified: Apr 20, 2025
    Published: Aug 20, 2017
    Items Per Page
    Connect2id Vulnerabilities & Security CVEs | CVE-DB