Intel

AIKIDO-2025-10657

joserfc is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource Consumption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 2, 2025

20

Low Risk

This Affects:

Pythonjoserfc
1.2.0 - 1.3.3
Fixed in 1.3.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Denial of Service due to insufficient content size validation in JWS and JWE components. The vulnerability allows attackers to send gigantic JWS or JWE payloads that are processed without size checks, consuming excessive memory and CPU resources. An attacker can exploit this by crafting large messages that overwhelm the system during parsing, potentially leading to service unavailability or crashes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

joserfc is vulnerable to Uncontrolled Resource Consumption in versions 1.2.0 - 1.3.3.

How to fix this

Upgrade the joserfc library to the patch version.