Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Python Jose
MEDIUM 5.3
CVE-2024-29370
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malici…
Patch available
Fix from $1,600
2025-12-17
Python Jose
MEDIUM 6.5
CVE-2024-33663
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Fix: after 3.3.0
Fix from $1,600
2024-04-26
Python Jose
MEDIUM 5.3
CVE-2024-33664
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE…
Fix: after 3.3.0
Fix from $1,600
2024-04-26
Python Jose
CRITICAL 9.8
CVE-2016-7036
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
Fix: after 1.3.1
Fix from $2,300
2017-01-23