CVE-2026-27932 is a resource exhaustion vulnerability in the joserfc Python library (versions 1.6.2 and earlier) that allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. This occurs when decrypting a JSON Web Encryption (JWE) token using PBES2 algorithms, as the library fails to validate or bound the 'p2c' parameter, leading to excessive PBKDF2 iterations. The vulnerability has a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low attack complexity, resulting in a high impact on availability. While there is no known active exploitation, exploit code, or KEV listing, it has garnered some community discussion and media coverage, primarily concerning security updates for openSUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.2CPE matchmatch criteria | cpe:2.3:a:hsiaoming:joserfc:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.