CVE-2024-29370

MEDIUM

python-jose < 3.4.0 - Denial of Service via Malicious JWE Token Decompression

Title source: llm
STIX 2.1

Description

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Patch
https://github.com/mpdavis/python-jose/issues/344

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-409
Status published
Products (2)
pypi/python-jose 0 - 3.4.0PyPI
python-jose_project/python-jose 3.3.0
Published Dec 17, 2025
Tracked Since Feb 18, 2026