Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-6773

CVE-2025-53864 Denial of service flaw in Connect2id Nimbus JOSE + JWT

XMLWordPrintable

      Description
      A denial of service flaw has been discovered in Connect2id Nimbus JOSE + JWT. This issue can allow a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set.

      Mitigation
      Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

      Additional information
      Bugzilla 2379485: com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

              Unassigned Unassigned
              rh-ee-ocorriga Owen Corrigan
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: