JWT Bomb Vulnerability in python-jose
CVE-2024-33664

Currently unrated

Key Information:

Vendor
CVE Published:
26 April 2024

What is CVE-2024-33664?

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

References

Timeline

  • Vulnerability published

.