VDB
RHSA-2025:2416
RHSA-2025:2416
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in the Nimbus Jose JWT package. By crafting a JWE with an excessively large p2c value, an attacker can trigger significant resource consumption during decryption, potentially leading to application slowdown or unavailability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Streams for Apache Kafka 2.9.0 |
Timeline
- Mar 5, 2025 CVE Published
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2316271 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2327264 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-8184 advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/30 advisory
- https://access.redhat.com/security/cve/CVE-2024-9355 advisory
- https://github.com/golang-fips/openssl/pull/198 advisory
- https://go.dev/cl/591255 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-31141 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-31141 advisory
- https://lists.apache.org/thread/9whdzfr0zwdhr364604w5ssnzmg4v2lv advisory
- https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3 advisory
- https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv advisory
- https://access.redhat.com/security/cve/CVE-2024-47554 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-47554 advisory
- https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1 advisory
- https://access.redhat.com/errata/RHSA-2025:2416 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2295310 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2309764 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2315719 issue
…and 22 more