REDHAT-BUG-2524147: Medium severity jwcrypto JWE.deserialize() vulnerability

Published Aug 25, 2026
·
Updated

The compact JWE fallback in JWE.deserialize() splits attacker-controlled token text on every period delimiter before checking that the compact serialization has the required five segments. A malformed token containing millions of periods can therefore force a large delimiter-derived list allocation and raise MemoryError before jwcrypto reaches its normal malformed-token rejection, which can degrade availability for services that parse untrusted JWE values.

Affected Software

1 affected component
jwcrypto JWE.deserialize()

Event History

Aug 25, 2026
Data Sourced
via Red Hat·09:56 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to availability impact?

Services that pass untrusted JWE values to jwcrypto's JWE.deserialize() are exposed. The issue can degrade availability when such input is processed.

2

What must an attacker provide to trigger the issue?

An attacker needs to supply a malformed compact JWE token containing millions of period delimiters. The token is split on every period before the required five-segment structure is checked.

3

How can the issue appear during operation?

Processing the malformed token can cause a large delimiter-derived list allocation and raise MemoryError before the normal malformed-token rejection occurs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203