VDB

CVE-2026-80179

CVE-2026-80179 PUBLISHED CVSS 5.9 MEDIUM

Reported by redhat · Published August 27, 2026

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.

Risk Scores

CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenStack Platform 16.2
Red HatRed Hat OpenStack Platform 16.2
Red HatRed Hat OpenStack Platform 16.2

…and 30 more

Timeline

  • Aug 27, 2026 CVE Published
  • Aug 28, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score

References

  • vdb-entryx_refsource_REDHAT
  • RHBZ#2524147 issue-trackingx_refsource_REDHAT
Open in Interactive Console →
$ Console Community · 100/wk Open console ›