Hsiaoming develops joserfc, a cryptographic library for JWT and JOSE operations, with identified vulnerabilities centered on resource exhaustion and denial-of-service conditions arising from unbounded resource allocation. The recurring weakness reflects the parsing and validation demands inherent to cryptographic token processing where untrusted input can trigger excessive computation or memory consumption. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hsiaoming over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65015HIGH joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to | Nov 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-27932HIGH joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerabilit | Mar 3, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hsiaoming.
Media articles that mention a CVE ID that affects a product developed by Hsiaoming — matched by CVE ID, not by vendor name.