CVE-2026-33204
EUVD-2026-1387120.03.2026, 23:16
SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kelvinmo | simplejwt | 𝑥 < 1.1.1 |
𝑥
= Vulnerable software versions