CVE-2026-39373

Aliases:GHSA-fjrm-76x2-c4q4PYSEC-2026-70RHSA-2026:19042RHSA-2026:19197DEBIAN-CVE-2026-39373CGA-28ff-hrgr-jxhrCGA-3r82-24c2-m5fqCGA-478w-mw75-fgrqCGA-49gr-p6vr-49g3CGA-5qw3-9pf5-gr9qCGA-5vj4-4764-44x4CGA-5xp3-2rx9-4c76CGA-6x2h-5xpw-2rvhCGA-7xh3-6r4p-8v99CGA-8rr4-p576-wmhwCGA-c7pr-x2p4-hw64CGA-fjhv-4vg2-vcwjCGA-h536-g4f8-p3frCGA-jq5m-j3g8-w234CGA-mp2g-5fcm-mf2jCGA-pr29-ghx7-62jwCGA-pxxh-6432-j9fcCGA-43w5-7vc7-h429CGA-5fq5-m64r-rvgjCGA-cvvp-v7hh-2x3mCGA-g2vv-xwx8-83rfCGA-hh5j-p45f-4hx6CGA-jh9w-7rx6-g46hCGA-jv7m-cw2c-jhg5CGA-m779-xrwq-gqx4CGA-p3fp-764q-4rm9CGA-q9mf-f779-9hwqCGA-qcg5-f53j-26c8CGA-r359-vh9c-x5jmCGA-r8hp-hwc4-m4xgCGA-x6h3-9jhx-ch2jCGA-xv72-c4gx-8wrr
Analyzed
Published: 07 Apr 2026, 19:35
Last modified:07 Apr 2026, 20:22

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.29% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

07 Apr 2026, 19:35
Published
Vulnerability first disclosed
07 Apr 2026, 20:22
Last Modified
Vulnerability information updated

Description

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.29% Percentile: 22%

Techniques & Countermeasures

  • CWE-409Improper Handling of Highly Compressed Data (Data Amplification)

    The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Systems

  • chainguardauthentik-2025.12

    < 2025.12.4-r5

  • chainguardauthentik-2026.2

    < 2026.2.1-r5

  • chainguardauthentik-fips-2025.12

    < 2025.12.4-r4

  • chainguardauthentik-fips-2026.2

    < 2026.2.1-r4

  • chainguardawx

    < 24.6.1-r42

  • chainguardkeep-api

    < 0.51.0-r4 | < 0.51.0-r3

  • chainguardkeep-api-fips

    < 0.51.0-r3

  • chainguardpy3-jwcrypto

    < 1.5.7-r0

  • chainguardpy3.10-jwcrypto

    < 1.5.7-r0

  • chainguardpy3.11-jwcrypto

    < 1.5.7-r0

  • chainguardpy3.12-jwcrypto

    < 1.5.7-r0

  • chainguardpy3.13-jwcrypto

    < 1.5.7-r0

  • wolfipy3-jwcrypto

    < 1.5.7-r0

  • wolfipy3.10-jwcrypto

    < 1.5.7-r0

  • wolfipy3.11-jwcrypto

    < 1.5.7-r0

  • wolfipy3.12-jwcrypto

    < 1.5.7-r0

  • wolfipy3.13-jwcrypto

    < 1.5.7-r0

  • debianpython-jwcrypto

    all | all | < 1.5.6-1.1~deb13u1 | < 1.5.6-1.1

  • latchsetjwcrypto

    < 1.5.7

  • PyPIjwcrypto

    ≤ 1.5.6 | < 1.5.7

  • redhatpython-jwcrypto

    < 0:1.5.6-5.el10_2 | < 0:1.5.6-3.el9_8

  • redhatpython3-jwcrypto

    < 0:1.5.6-5.el10_2 | < 0:1.5.6-3.el9_8

References (16)