Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80179— Jwcrypto: jwcrypto: denial of service via malformed jwe tokens

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

jwcrypto 中发现了缺陷。远程攻击者可以发送一个经过特殊构造的 JSON Web 加密(JWE)令牌,其中包含大量的周期分隔符。这个格式错误的令牌可以强制 JWE.deserialize() 函数分配过多的内存,从而导致 MemoryError(内存错误)。这会导致处理不受信任的 JWE 值的服务发生拒绝服务(DoS)。

CVSS 5.9 · Medium EPSS 0.25% · P16

Affected Version Matrix 25

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2 any affected
any affected
any affected
any affected
any affected
any affected
any affected
any affected
… +5 more rows
Red Hat Red Hat Enterprise Linux 10 any unknown
Red Hat Red Hat Enterprise Linux 9 any unknown
Red Hat Red Hat OpenShift AI (RHOAI) any affected
any affected
Red Hat Red Hat OpenStack Platform 16.2 any affected
any affected
any affected
any affected
any affected
any affected
any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80179

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Jwcrypto: jwcrypto: denial of service via malformed jwe tokens
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift AI (RHOAI) - cpe:/a:redhat:openshift_ai
Red Hat Red Hat OpenShift AI (RHOAI) - cpe:/a:redhat:openshift_ai
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2

II. Public POCs for CVE-2026-80179

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80179

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80179 (3)

Same Patch Batch · Red Hat · 2026-08-27 · 6 CVEs total

CVE-2026-78002 7.5 HIGH Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun
CVE-2026-5680 7.5 HIGH Undertow-core: undertow: denial of service via websocket permessage-deflate processing
CVE-2026-81658 6.5 MEDIUM Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup
CVE-2026-81668 5.4 MEDIUM Rubygem-katello: cross-tenant content view filter rule access and modification via unautho
CVE-2026-81893 4.7 MEDIUM Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery

IV. Related Vulnerabilities

V. Comments for CVE-2026-80179

No comments yet


Leave a comment