Information Exposure Affecting python-jwcrypto package, versions <0.3.2-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
2.25% (82nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-PYTHONJWCRYPTO-19402154
  • published28 Aug 2026
  • disclosed1 Sept 2016

Introduced: 1 Sep 2016

CVE-2016-6298  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade Echo:latest python-jwcrypto to version 0.3.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-jwcrypto package and not the python-jwcrypto package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).

CVSS Base Scores

version 3.1