PT-2026-50551 · Pypi · Joserfc
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
joserfc versions 1.3.4 through 1.6.5
Description
joserfc is a Python library implementing JSON Object Signing and Encryption (JOSE) standards. The library fails to apply the
JWSRegistry.max payload length limit when processing RFC7797 b64=false JWS payloads. While standard JWS compact and flattened JSON paths correctly reject oversized payloads with an ExceededSizeError, the RFC7797 unencoded payload paths bypass this check. This allows the successful deserialization of payloads exceeding the configured size limit, which can lead to resource exhaustion and pose an availability risk for applications accepting lower-trust JWS values.Recommendations
Update to version 1.6.7.
Exploit
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Joserfc