OESA-2026-3636

    Dashboard / Vulnerabilities / OESA-2026-3636

    OESA-2026-3636

    Published: 5 Sept 2026Last Modified: 5 Sept 2026
    Upstream:

    Summary: python-jwcrypto security update

    Details: Implements JWK, JWS, JWE specifications with python-cryptography Security Fix(es): JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.(CVE-2026-39373)

    Affected packages

    Package

    Name: python-jwcrypto

    Purl: pkg:rpm/openEuler/python-jwcrypto&distro=openEuler-22.03-LTS-SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.2-4.oe2203sp4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2026-3636 | CVE-DB