Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Latchset

First CVE: Sep 1, 2016Active for: 10 yearsTotal CVEs: 6

Latchset develops a focused set of cryptographic and PKCS#11 provider libraries including jwcrypto, JOSE, and pkcs11-provider that serve as building blocks in authentication and encryption infrastructure. Its vulnerability profile centers on resource-handling and information-disclosure weaknesses—uncontrolled resource consumption, improper handling of compressed data, exposure of sensitive material, and side-channel protection gaps—that reflect the parsing and state-management demands of cryptographic implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Latchset over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 1, 2016
9 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6258HIGH
A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerabi
Jan 30, 20248.122NONO
CVE-2024-28102MEDIUM
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious J
Mar 21, 20246.821NONO
CVE-2023-50967HIGH
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Mar 20, 20247.521NONO
CVE-2026-39373MEDIUM
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens
Apr 7, 20265.319NONO
CVE-2023-6681MEDIUM
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more re
Feb 12, 20245.318NONO
CVE-2016-6298MEDIUM
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attacker
Sep 1, 20165.316NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High2 (33.3%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High1 (16.7%)
None4 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Latchset.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Latchset — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Latchset's Products

View all 3 CNAs →

Top CWEs