CVE-2024-29370

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Configurations

No configuration.

History

17 Dec 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-409

17 Dec 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 16:16

Updated : 2025-12-18 15:07


NVD link : CVE-2024-29370

Mitre link : CVE-2024-29370

CVE.ORG link : CVE-2024-29370


JSON object : View

Products Affected

No product.

CWE
CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)