
CVE-2026-39373 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending craft… https://www.cve.org/CVERecord?id=CVE-2026-39373
Post summary
The post announces CVE‑2026‑39373, describing a memory exhaustion flaw in JWCrypto via crafted JWK/JWS/JWE data, with no evidence of exploits or patches.
