CVE-2025-53864Patch

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Peaked 1d ago at 2 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-21: 103-1103-21
Signal classification1 categories
Patch
3100.0%
Classification over time
DateTotalLabels
2026-03-112
Patch2
2026-03-211
Patch1
Full discourse3 posts
  • GCP Weekly@gcpweekly
    Patch

    2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to 2/3

    Post summary

    The text announces that several CVEs have been fixed in a recent update of the Dataproc Metastore Proxy.

    1000032
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and CVE-2025-33042. 2/4

    Post summary

    The note lists package revisions that have been updated to fix the specified CVEs, presenting patch information rather than new exploits or evidence of active attacks.

    1000098
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.1.110-ubuntu20-arm 2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and 2/4

    Post summary

    This release notes the application of patches for several CVEs, with no mention of exploits or PoCs, indicating a vendor update rather than active exploitation.

    1000088
    1.8K followersView on X

Explore more