python-jose project records
4 published records for vendor python-jose project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-361 7PK - Time and State1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-7036No exploit | python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.python-jose project · python-jose · CWE-361 | Critical9.8 | — | 2.1% | Jan 23, 2017 |
26Monitor | CVE-2024-33663No exploit | python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats.python-jose project · python-jose · CWE-327 | Medium6.5 | — | 0.3% | Apr 25, 2024 |
21Monitor | CVE-2024-33664No exploit | python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryppython-jose project · python-jose · CWE-400 | Medium5.3 | — | 0.8% | Apr 25, 2024 |
21Monitor | CVE-2024-29370No exploit | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by craftingpython-jose project · python-jose · CWE-409 | Medium5.3 | — | 0.2% | Dec 17, 2025 |
- CVE-2016-703640Plan
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
CriticalCVSS 9.8No exploitEPSS 2%python-jose project · python-joseJan 23, 2017
- CVE-2024-3366326Monitor
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats.
MediumCVSS 6.5No exploitEPSS 0%python-jose project · python-joseApr 25, 2024
- CVE-2024-3366421Monitor
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryp
MediumCVSS 5.3No exploitEPSS 1%python-jose project · python-joseApr 25, 2024
- CVE-2024-2937021Monitor
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting
MediumCVSS 5.3No exploitEPSS 0%python-jose project · python-joseDec 17, 2025