Skip to content
Noroxi

python-jose project records

4 published records for vendor python-jose project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.

    CriticalCVSS 9.8No exploitEPSS 2%

    python-jose project · python-joseJan 23, 2017

  • python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats.

    MediumCVSS 6.5No exploitEPSS 0%

    python-jose project · python-joseApr 25, 2024

  • python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryp

    MediumCVSS 5.3No exploitEPSS 1%

    python-jose project · python-joseApr 25, 2024

  • In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting

    MediumCVSS 5.3No exploitEPSS 0%

    python-jose project · python-joseDec 17, 2025