The Python Jose Project maintains a focused cryptographic library for JWT (JSON Web Token) handling in Python applications, where despite a narrow product footprint it serves as a critical dependency across authentication and API-security implementations. The observed vulnerability disclosures in this library are sparse and do not yet surface a durable pattern of recurrent weakness classes. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Python Jose Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7036CRITICAL python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys. | Jan 23, 2017 | 9.8 | 24 | NO | NO |
CVE-2024-33663MEDIUM python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | Apr 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-29370MEDIUM In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) t | Dec 17, 2025 | 5.3 | 19 | NO | NO |
CVE-2024-33664MEDIUM python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression | Apr 26, 2024 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Jose Project.
Media articles that mention a CVE ID that affects a product developed by Python Jose Project — matched by CVE ID, not by vendor name.