-
Notifications
You must be signed in to change notification settings - Fork 464
Open
Labels
bugSomething isn't workingSomething isn't working
Description
While working on guardrails Project, I discovered a Denial of Service (DoS) vulnerability in the authlib package. The issue occurs due to unbounded JOSE segment sizes — a malicious actor can craft an oversized JWS/JWT token that consumes excessive CPU and memory during decoding and verification.
CVE Link
CVE Report
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working