CVE-2026-33204: Kelvinmo Simplejwt
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.
Affected products
- Kelvinmo Simplejwt: before 1.1.1 (fixed in 1.1.1)
Published 2026-03-20. Last modified 2026-06-17.