{"id":"CVE-2026-39373","title":"JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)","summary":"A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE toke…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","affected":["ansible_automation_platform 2","enterprise_linux 7","enterprise_linux 8","ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","ansible_automation_platform 2.6"],"patched":["ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","ansible_automation_platform 2.6"],"published":"2026-04-07","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:51:26+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-39373"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456187"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-39373"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39373"},{"url":"https://github.com/latchset/jwcrypto/security/advisories/GHSA-fjrm-76x2-c4q4"},{"url":"https://access.redhat.com/errata/RHSA-2026:59135"},{"url":"https://access.redhat.com/errata/RHSA-2026:13512"},{"url":"https://access.redhat.com/errata/RHSA-2026:59136"},{"url":"https://access.redhat.com/errata/RHSA-2026:13508"},{"url":"https://access.redhat.com/errata/RHSA-2026:19042"},{"url":"https://access.redhat.com/errata/RHSA-2026:19197"},{"url":"https://access.redhat.com/errata/RHSA-2026:42132"},{"url":"https://github.com/latchset/jwcrypto/commit/25db861d8b29434838669a94a843af03d29ea6ed"},{"url":"https://github.com/latchset/jwcrypto"},{"url":"https://github.com/latchset/jwcrypto/releases/tag/v1.5.7"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2026-70.yaml"}],"tags":["csaf","vex","red-hat","osv","pip","score-dispute"],"epss":0.00294,"epssPercentile":0.22232,"aliases":["GHSA-fjrm-76x2-c4q4","PYSEC-2026-70"],"ecosystem":"pip","scores":{"vendor":7.5,"osv":5.3},"ingestedAt":"2026-09-12T03:13:01.692Z","slug":"CVE-2026-39373","body":"## Overview\n\nA flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE tokens that use ZIP compression. While the input token size is limited, the decompressed output size is not validated, allowing an attacker to cause excessive memory consumption. This can lead to memory exhaustion on affected systems, resulting in a Denial of Service (DoS).\n\n## Vendor advisories\n\n- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)\n- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)\n- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)\n- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)\n- **RHSA-2026:19042** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19042)\n- **RHSA-2026:19197** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19197)\n- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)\n- **Red Hat VEX** · Low · affected: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json)\n\n**JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens** — rated Low by Red Hat. Released 2026-04-07, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Ansible Automation Platform 2.6\n\nNo fix planned:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2\n- Red Hat Hardened Images\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59135\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:13512\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59136\n\n## Package advisory (CVE-2026-39373)\n\nAffected packages:\n\n- `jwcrypto < 1.5.7`\n\nPatched in:\n\n- `jwcrypto 1.5.7`\n\nSource: https://osv.dev/vulnerability/GHSA-fjrm-76x2-c4q4","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":204225,"id":"CVE-2026-39373","ts":1789490240341,"field":"cvss","old":"5.3","new":"7.5"},{"seq":204224,"id":"CVE-2026-39373","ts":1789490240341,"field":"severity","old":"medium","new":"high"}]}