CVE-2026-39373
Vulnerability Summary
Timeline
Description
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.29%• Percentile: 22%
Techniques & Countermeasures
- CWE-409•Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Affected Systems
- chainguard•authentik-2025.12
< 2025.12.4-r5
- chainguard•authentik-2026.2
< 2026.2.1-r5
- chainguard•authentik-fips-2025.12
< 2025.12.4-r4
- chainguard•authentik-fips-2026.2
< 2026.2.1-r4
- chainguard•awx
< 24.6.1-r42
- chainguard•keep-api
< 0.51.0-r4 | < 0.51.0-r3
- chainguard•keep-api-fips
< 0.51.0-r3
- chainguard•py3-jwcrypto
< 1.5.7-r0
- chainguard•py3.10-jwcrypto
< 1.5.7-r0
- chainguard•py3.11-jwcrypto
< 1.5.7-r0
- chainguard•py3.12-jwcrypto
< 1.5.7-r0
- chainguard•py3.13-jwcrypto
< 1.5.7-r0
- wolfi•py3-jwcrypto
< 1.5.7-r0
- wolfi•py3.10-jwcrypto
< 1.5.7-r0
- wolfi•py3.11-jwcrypto
< 1.5.7-r0
- wolfi•py3.12-jwcrypto
< 1.5.7-r0
- wolfi•py3.13-jwcrypto
< 1.5.7-r0
- debian•python-jwcrypto
all | all | < 1.5.6-1.1~deb13u1 | < 1.5.6-1.1
- latchset•jwcrypto
< 1.5.7
- PyPI•jwcrypto
≤ 1.5.6 | < 1.5.7
- redhat•python-jwcrypto
< 0:1.5.6-5.el10_2 | < 0:1.5.6-3.el9_8
- redhat•python3-jwcrypto
< 0:1.5.6-5.el10_2 | < 0:1.5.6-3.el9_8
References (16)
- https://github.com/latchset/jwcrypto/security/advisories/GHSA-fjrm-76x2-c4q4
- https://nvd.nist.gov/vuln/detail/CVE-2026-39373
- https://github.com/latchset/jwcrypto
- https://github.com/latchset/jwcrypto/commit/25db861d8b29434838669a94a843af03d29ea6ed
- https://github.com/latchset/jwcrypto/releases/tag/v1.5.7
- https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2026-70.yaml
- https://access.redhat.com/errata/RHSA-2026:19042
- https://access.redhat.com/security/updates/classification/#low
- https://bugzilla.redhat.com/show_bug.cgi?id=2456187
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19042.json
- https://access.redhat.com/security/cve/CVE-2026-39373
- https://www.cve.org/CVERecord?id=CVE-2026-39373
- https://access.redhat.com/errata/RHSA-2026:19197
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19197.json
- https://security-tracker.debian.org/tracker/CVE-2026-39373
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39373.json