PT-2026-50551 · Pypi · Joserfc

·

CVE-2026-48990

·

Published

2026-06-17

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions joserfc versions 1.3.4 through 1.6.5
Description joserfc is a Python library implementing JSON Object Signing and Encryption (JOSE) standards. The library fails to apply the JWSRegistry.max payload length limit when processing RFC7797 b64=false JWS payloads. While standard JWS compact and flattened JSON paths correctly reject oversized payloads with an ExceededSizeError, the RFC7797 unencoded payload paths bypass this check. This allows the successful deserialization of payloads exceeding the configured size limit, which can lead to resource exhaustion and pose an availability risk for applications accepting lower-trust JWS values.
Recommendations Update to version 1.6.7.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48990
GHSA-WPHV-VFRH-23Q5
OPENSUSE-SU-2026:11067-1
PYSEC-2026-2530
RHSA-2026:25039

Affected Products

Joserfc