{
  "title": "JWE decrypt: no limit on number of recipients (hardening)",
  "category": "security",
  "type": "hardening",
  "severity": "medium",
  "cvss": {
    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "score": null
  },
  "ecosystem": "python",
  "project": {
    "owner": "latchset",
    "repo": "jwcrypto",
    "url": "https://github.com/latchset/jwcrypto"
  },
  "affected_versions": [
    "jwcrypto 1.6.1 and HEAD"
  ],
  "status": "fixed",
  "disclosure": {
    "channel": "pr",
    "ghsa_id": null,
    "cve_id": null,
    "url": "https://github.com/latchset/jwcrypto/pull/402",
    "reported_at": "2026-10-04T00:00:00+03:00",
    "published_at": "2026-10-06T01:18:39+03:00"
  },
  "summary": "JWE.decrypt tried every entry in the recipients array with no cap; public hardening PR adds an overridable default_max_recipients (10) and an early exit after the first successful decrypt.",
  "discovered_at": "2026-10-03T00:00:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "updated_at": "2026-10-06T01:52:00+03:00",
  "pr": {
    "url": "https://github.com/latchset/jwcrypto/pull/402",
    "state": "merged",
    "merged_at": "2026-10-06T01:18:39+03:00"
  },
  "id": "security/python/latchset__jwcrypto/2026-10-03-pbes2-recipients-cpu-amplification",
  "resolution": "hardening (maintainer: not a CVE); merged by simo5"
}
