© 2025-2026 PySpect
First version without a known vulnerability: 1.5.7
JWCrypto: JWE ZIP decompression bomb
Fixed in: 1.5.7
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
Fixed in: 1.5.6
DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value
Fixed in: 1.5.1
jwcrypto token substitution can lead to authentication bypass
Fixed in: 1.4
jwcrypto lacks the Random Filling protection mechanism
Fixed in: 0.3.2, eb5be5bd94c8cae1d7f3ba9801377084d8e5a7ba, 0.4.0