---
id: CVE-2026-39373
title: >-
  JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted
  compressed JWE tokens (CVE-2026-39373)
summary: >-
  A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON
  Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An
  unauthenticated attacker can exploit this vulnerability by sending specially
  crafted JWE toke…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat Ansible Automation Platform 2.5 for RHEL 8
affected:
  - ansible_automation_platform 2
  - enterprise_linux 7
  - enterprise_linux 8
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - ansible_automation_platform 2.6
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - ansible_automation_platform 2.6
published: '2026-04-07'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T17:51:26+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-39373'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2456187'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-39373'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39373'
  - url: >-
      https://github.com/latchset/jwcrypto/security/advisories/GHSA-fjrm-76x2-c4q4
  - url: 'https://access.redhat.com/errata/RHSA-2026:59135'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13512'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59136'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13508'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19042'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19197'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42132'
  - url: >-
      https://github.com/latchset/jwcrypto/commit/25db861d8b29434838669a94a843af03d29ea6ed
  - url: 'https://github.com/latchset/jwcrypto'
  - url: 'https://github.com/latchset/jwcrypto/releases/tag/v1.5.7'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2026-70.yaml
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - score-dispute
epss: 0.00434
epssPercentile: 0.35071
aliases:
  - GHSA-fjrm-76x2-c4q4
  - PYSEC-2026-70
ecosystem: pip
scores:
  vendor: 7.5
  osv: 5.3
ingestedAt: '2026-09-12T03:13:01.692Z'
---

## Overview

A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE tokens that use ZIP compression. While the input token size is limited, the decompressed output size is not validated, allowing an attacker to cause excessive memory consumption. This can lead to memory exhaustion on affected systems, resulting in a Denial of Service (DoS).

## Vendor advisories

- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)
- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)
- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)
- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)
- **RHSA-2026:19042** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19042)
- **RHSA-2026:19197** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19197)
- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)
- **Red Hat VEX** · Low · affected: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39373.json)

**JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens** — rated Low by Red Hat. Released 2026-04-07, updated 2026-09-14.

Affected:

- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Ansible Automation Platform 2.6

No fix planned:

- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2
- Red Hat Hardened Images

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59135
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:13512
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59136

## Package advisory (CVE-2026-39373)

Affected packages:

- `jwcrypto < 1.5.7`

Patched in:

- `jwcrypto 1.5.7`

Source: https://osv.dev/vulnerability/GHSA-fjrm-76x2-c4q4
