• imports/c10s/python-jwcrypto-1.5.6-5.el10 4c6c2f53c0

    Ghost released this 2026-04-16 22:48:48 +00:00 | -52 commits to c8s-stream-DL1 since this release

    Backport upstream commit 25db861d to fix CVE-2026-39373.
    This introduces a maximum plaintext size limit (defaulting to 100MB)
    during JWE decryption to mitigate memory exhaustion and decompression
    bomb attacks when processing highly compressed malicious JWE payloads.

    Resolves: RHEL-166011
    Signed-off-by: Rafael Guterres Jeffman rjeffman@redhat.com

    Downloads