CVE-2026-39373 is a memory exhaustion vulnerability in JWCrypto versions prior to 1.5.7, affecting the library's handling of JWE tokens with ZIP compression. An unauthenticated attacker can craft malicious JWE tokens that bypass the existing 250KB input size limit by decompressing to approximately 100MB, causing denial of service on memory-constrained systems. The vulnerability exists because the previous patch for CVE-2024-28102 validated input size but failed to restrict decompressed output size. The attack requires no authentication, network access, or user interaction, making it trivially easy to execute. The CVSS score of 5.3 (Medium) reflects the availability impact, with no confidentiality or integrity compromise. However, the practical impact could be significant for resource-limited deployments, potentially causing service disruptions. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the KEV catalog and remains inactive on threat tracking lists, indicating minimal community attention at this time. However, organizations running JWCrypto should prioritize upgrading to version 1.5.7 to eliminate this attack vector, particularly if operating in memory-constrained environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.7CPE matchmatch criteria | cpe:2.3:a:latchset:jwcrypto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.