joserfc vulnerabilities
CVEs whose affected-version data names the joserfc package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV
CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
▾ Sunlitjoserfc · joserfcEPSS 0.16%via OSV
CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
▾ Twilightjoserfc · joserfcEPSS 0.43%via OSV
CVE-2025-65015Criticaljoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
▾ Midnightjoserfc · joserfcEPSS 0.41%via OSV