A critical vulnerability, tracked as CVE-2025-65015, has been identified in the Python library joserfc, which implements several JSON Object Signing and Encryption (JOSE) standards. The flaw affects versions 1.3.3 to before 1.3.5 and 1.4.0 to before 1.4.2, where the library's error handling embeds non-decoded JWT token parts into exception messages. If an attacker sends an oversized JWT token, the resulting exception can cause Python logging or diagnostic tools to process extremely large log messages, potentially exhausting server resources. This issue is particularly severe in environments lacking a properly configured production-grade web server in front of the Python application, as the full JWT payload is loaded into memory before the error is raised.
The vulnerability has been addressed in joserfc versions 1.3.5 and 1.4.2. Security advisories emphasize the risk of denial-of-service (DoS) attacks if the flaw is exploited, as attackers can repeatedly trigger resource exhaustion by sending arbitrarily large JWT tokens. Organizations using affected versions of joserfc are urged to update to the patched releases to mitigate the risk of exploitation and ensure that web server configurations are robust enough to prevent oversized request headers from reaching backend applications.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent public reporting described CVE-2025-65015 as a critical joserfc vulnerability that could let attackers exhaust server resources via oversized JWT tokens. This appears to be follow-on coverage of the same disclosed flaw rather than a separate incident.
A vulnerability identified as CVE-2025-65015 was disclosed affecting joserfc. The issue involves possible uncontrolled resource consumption when arbitrarily large JWT token payloads are logged, potentially allowing server resource exhaustion.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.