CVE-2023-52428: CONNECT2ID Nimbus Jose+jwt
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Affected products
- CONNECT2ID Nimbus Jose+jwt: before 9.37.2 (fixed in 9.37.2)
Published 2024-02-11. Last modified 2026-06-17.