Latchset develops a focused set of cryptographic and PKCS#11 provider libraries including jwcrypto, JOSE, and pkcs11-provider that serve as building blocks in authentication and encryption infrastructure. Its vulnerability profile centers on resource-handling and information-disclosure weaknesses—uncontrolled resource consumption, improper handling of compressed data, exposure of sensitive material, and side-channel protection gaps—that reflect the parsing and state-management demands of cryptographic implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Latchset over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6258HIGH A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerabi | Jan 30, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-28102MEDIUM JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious J | Mar 21, 2024 | 6.8 | 21 | NO | NO |
CVE-2023-50967HIGH latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | Mar 20, 2024 | 7.5 | 21 | NO | NO |
CVE-2026-39373MEDIUM JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens | Apr 7, 2026 | 5.3 | 19 | NO | NO |
CVE-2023-6681MEDIUM A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more re | Feb 12, 2024 | 5.3 | 18 | NO | NO |
CVE-2016-6298MEDIUM The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attacker | Sep 1, 2016 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Latchset.
Media articles that mention a CVE ID that affects a product developed by Latchset — matched by CVE ID, not by vendor name.