VendorsLatchsetjwcryptoany version
Vulnerabilities

Latchset organization JWCrypto any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-28102
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
Published 2024-03-06 · Analyzed
6.8EPSS 0.010
CVE-2016-6298
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
Published 2016-09-01 · Modified
5.3EPSS 0.022
CVE-2023-6681
Jwcrypto: denail of service via specifically crafted jwe
Published 2024-02-12 · Modified
5.3EPSS 0.009
CVE-2026-39373
JWCrypto: JWE ZIP decompression bomb
Published 2026-04-07 · Analyzed
5.3EPSS 0.004