JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-jwcrypto | May 27, 2026 | May 19, 2026 |
| Amazon Linux Ami 2 | — | Upgrade python-jwcrypto | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade python-jwcrypto | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade yamllintUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3-pytokensUpgrade python3.12-pulpcoreUpgrade python3.12-cffi-debugsourceUpgrade python3-wheel-wheelUpgrade python3.12-cryptography-debuginfoUpgrade receptorctlUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-pysequoia-debugsourceUpgrade python3.12-django-ansible-base+activitystreamUpgrade automation-controller-uiUpgrade python3.12-cryptography-debugsourceUpgrade python3.12-galaxy-importerUpgrade ansible-coreUpgrade receptorUpgrade python3.12-cffiUpgrade python3.12-dynaconfUpgrade automation-gateway-proxyUpgrade automation-eda-controller-baseUpgrade python3.12-pathspecUpgrade python3-pathspecUpgrade python3.12-django-ansible-base+resource_registryUpgrade receptor-debuginfoUpgrade ansible-testNo solution existsUpgrade automation-controller-cliUpgrade python3.12-django-ansible-baseUpgrade python3.12-pytokens-debugsourceUpgrade automation-gatewayUpgrade automation-eda-controller-base-servicesUpgrade automation-gateway-configUpgrade python3.12-django-ansible-base+authenticationUpgrade python3.12-jwcryptoUpgrade automation-hubUpgrade python3.12-pyjwtUpgrade python-pytokens-debugsourceUpgrade python3.12-cffi-debuginfoUpgrade python3.12-django-ansible-base+rest_filtersUpgrade python3.12-pulp-containerUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade python3.12-galaxy-ngUpgrade python3.12-pyjwt+cryptoUpgrade python3-jwcryptoUpgrade automation-controller-serverUpgrade automation-platform-uiUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade receptor-debugsourceUpgrade automation-gateway-serverUpgrade python3.12-pysequoiaUpgrade automation-eda-controllerUpgrade automation-controllerUpgrade automation-gateway-proxy-serverUpgrade automation-controller-venv-towerUpgrade python3.12-pyasn1-modulesUpgrade python3.12-markdownUpgrade python3.12-django-ansible-base+feature_flagsUpgrade python3.12-cryptographyUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-pyOpenSSLUpgrade python3.12-pytokens-debuginfoUpgrade python3.12-pyasn1Upgrade python3.12-pysequoia-debuginfoUpgrade python3.12-pytokensUpgrade python3-pytokens-debuginfoUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-blackUpgrade python3-blackUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-gateway-proxy-server-debuginfoUpgrade ansible-lint | May 6, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub