Denial of Service Flaw in jwcrypto Affects Applications Utilizing Key Import APIs
CVE-2026-92091
5.9MEDIUM
What is CVE-2026-92091?
A flaw exists in the jwcrypto library, where the JWK.import_key() function inadequately validates the key_ops JWK member. This leads to a vulnerability that allows an unauthenticated remote attacker to submit a JWK with a significant key_ops array to applications utilizing vulnerable public key-import APIs. The resulting excessive CPU usage can lead to service disruptions, presenting a risk to application availability. Remediation measures should be undertaken to prevent exploitation.