Connect2id develops the Nimbus JOSE+JWT library, a cryptographic and token-handling component embedded in OAuth and OpenID Connect implementations across identity and access-control infrastructure. Vulnerabilities observed in this library center on resource-exhaustion conditions, exceptional-case handling, and integrity-check and signature-validation weaknesses that reflect the parsing and cryptographic verification demands of JWT processing; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Connect2id over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17195CRITICAL Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a | Oct 15, 2019 | 9.8 | 38 | NO | NO |
CVE-2017-12974HIGH Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an I | Aug 20, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-12972HIGH In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifti | Aug 20, 2017 | 7.5 | 24 | NO | NO |
CVE-2023-52428HIGH In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the Passwor | Feb 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-53864MEDIUM Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT c | Jul 11, 2025 | 5.8 | 19 | NO | NO |
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack. | Aug 20, 2017 | 3.1 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Connect2id.
Media articles that mention a CVE ID that affects a product developed by Connect2id — matched by CVE ID, not by vendor name.