Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade jwcrypto to version 1.6.1 or higher.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the JWK.import_key() method, whose key_ops duplicate detection rescans the whole array for every element and enforces no size limit, making the check O(n^2) over untrusted parsed JWK data. An attacker can occupy a CPU core for minutes with a sub-megabyte request body, and exhaust a server with a handful of concurrent requests, by submitting a key such as {"kty":"oct","k":"AAAA","key_ops":[...]} carrying roughly 50,000 distinct operations. This requires the application to import attacker-supplied JWK or JWK Sets through import_key() or the related from_json() and import_keyset() entry points, as in dynamic client registration, DPoP, ACME account keys, or federated JWKS endpoints, and relying parties that import keys only from fixed trusted issuers are unexposed.