Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2528
  • PyPI/joserfc
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363) 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2530
  • PyPI/joserfc
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2529
  • PyPI/joserfc
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS) 13 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-gg9x-qcx2-xmrh
  • PyPI/joserfc
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363) 02 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-361
  • PyPI/joserfc
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads 29 Jun
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-wphv-vfrh-23q5
  • PyPI/joserfc
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization 26 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-w5r5-m38g-f9f9
  • PyPI/joserfc
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS) 02 Mar
  • Fix available
  • Severity - 7.5 (High)
GHSA-frfh-8v73-gjg4
  • PyPI/joserfc
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads 18 Nov 2025
  • Fix available
  • Severity - 9.2 (Critical)