Package impact

python PyPI / python-jose

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2016-7036 critical 9.8 9.8 10y ago python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys. debianpython
CVE-2024-29370 unknown 5mo ago In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an except… susedebianpython
CVE-2024-33663 unknown 2y ago python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. susedebianpython
CVE-2024-33664 unknown 2y ago python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT … susedebianpython