Executive brief
A vulnerability in the python-jose library, which is used to handle secure web tokens, could allow an attacker to crash or slow down a server. By sending a specially crafted, highly compressed token, an attacker can force the server to consume excessive memory and processing power during decompression. This can lead to a denial-of-service (DoS) condition, making the application unavailable to legitimate users.
Technical details
A denial-of-service (DoS) vulnerability exists in python-jose versions prior to 3.4.0 due to improper handling of highly compressed data (CWE-409). The `jwe.decrypt` function does not sufficiently limit the resources used when decompressing JSON Web Encryption (JWE) tokens. An unauthenticated remote attacker can exploit this by submitting a malicious JWE token with a high compression ratio, leading to significant memory allocation and CPU usage (a 'decompression bomb'). This was addressed in version 3.4.0 by implementing a 250 KB size limit on JWE tokens.
Affected products
- mpdavis python-jose < 3.4.0
Timeline
- 2024-03-18: disclosed: Initial issue reported on GitHub
- 2025-12-17: advisory: GitHub and NVD advisories published
- 2024-02-14: patched: Version 3.4.0 released with fix