Junglewise Threat Intelligence

CVE-2024-29370: python-jose denial of service via compressed JWE content

CVE-2024-29370 · Severity: medium · CVSS 5.3 · Published 2025-12-17

Technologies: python-jose (PyPI), Mpdavis Jose. Vendors: PyPI, Mpdavis.

Executive brief

A vulnerability in the python-jose library, which is used to handle secure web tokens, could allow an attacker to crash or slow down a server. By sending a specially crafted, highly compressed token, an attacker can force the server to consume excessive memory and processing power during decompression. This can lead to a denial-of-service (DoS) condition, making the application unavailable to legitimate users.

Technical details

A denial-of-service (DoS) vulnerability exists in python-jose versions prior to 3.4.0 due to improper handling of highly compressed data (CWE-409). The `jwe.decrypt` function does not sufficiently limit the resources used when decompressing JSON Web Encryption (JWE) tokens. An unauthenticated remote attacker can exploit this by submitting a malicious JWE token with a high compression ratio, leading to significant memory allocation and CPU usage (a 'decompression bomb'). This was addressed in version 3.4.0 by implementing a 250 KB size limit on JWE tokens.

Affected products

  • mpdavis python-jose < 3.4.0

Timeline

  • 2024-03-18: disclosed: Initial issue reported on GitHub
  • 2025-12-17: advisory: GitHub and NVD advisories published
  • 2024-02-14: patched: Version 3.4.0 released with fix

References

Related threats