CVE-2026-39373: Latchset Jwcrypto

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7.

Affected products

  • Latchset Jwcrypto: before 1.5.7 (fixed in 1.5.7)

Published 2026-04-07. Last modified 2026-07-24.