A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values. | |
| Title | Jwcrypto: jwcrypto: denial of service via malformed jwe tokens | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat enterprise Linux Redhat openshift Ai Redhat openstack |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:openshift_ai cpe:/a:redhat:openstack:16.2 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat enterprise Linux Redhat openshift Ai Redhat openstack |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-27T21:14:23.428Z
Reserved: 2026-08-25T21:13:03.622Z
Link: CVE-2026-80179
No data.
Status : Received
Published: 2026-08-28T00:18:20.337
Modified: 2026-08-28T00:18:20.337
Link: CVE-2026-80179
OpenCVE Enrichment
Updated: 2026-08-28T08:30:17Z
Weaknesses