Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-53864

19
FAUCET Score

CVE-2025-53864 affects Connect2id Nimbus JOSE + JWT versions 10.0.x before 10.0.2 and 9.37.x before 9.37.4, allowing a remote attacker to trigger a denial of service. This is due to uncontrolled recursion when processing deeply nested JSON objects within a JWT claim set. The vulnerability has a CVSS score of 5.8 (Medium), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in a partial availability impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 10.0.2CPE match
cpe:2.3:a:connect2id:nimbus_jose\+jwt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.8MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.81%
Probability of exploitation in next 30 days
EPSS Percentile
53.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0081 is in the 33rd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

mavenpatch availablevia ghsa
Product: com.nimbusds:nimbus-jose-jwtFixed in: 9.37.4
mavenpatch availablevia ghsa
Product: com.nimbusds:nimbus-jose-jwtFixed in: 10.0.2
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 3.0.0
View patch
redhatvendor investigatingvia redhat_api
Product: Cryostat 4Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel 4 for Quarkus 3Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 4Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel - HawtIO 4Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat build of QuarkusFixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: nimbus-jose-jwt
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: nimbus-jose-jwt

Vendor Advisories (2)

mavenGHSA-xwmg-2g98-w7v9medium

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

Jul 11, 2025
redhatCVE-2025-53864Moderate

com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

Jul 11, 2025

References

bitbucket.org / connect2id/nimbus-jose-jwt/commits/f7fb882cc08f027c9ceb874acec3b51c6222861c
bitbucket.org / connect2id/nimbus-jose-jwt/issues/583/stackoverflowerror-due-to-deeply-nested
bitbucket.org / connect2id/nimbus-jose-jwt/issues/593/back-port-cve-2025-53864-fix-to-9x-branch
github.com / google/gson/commit/1039427ff0100293dd3cf967a53a55282c0fef6b
github.com / google/gson/compare/gson-parent-2.11.0...gson-parent-2.12.0