Skip to main content

Mcpm: Authlib is vulnerable to Denial of Service via Oversized JOSE Segments (CVE-2025-61920)

0
High
Published: 08/13/2026 (08/13/2026, 17:13:14 UTC)
Source: GCVE Database
Product: mcpm

Description

Authlib versions up to 1.6.3 have a vulnerability in their JOSE implementation where oversized JWS/JWT header or signature segments can cause excessive CPU and memory consumption during verification, leading to denial of service. The vulnerability arises because the library accepts unbounded base64url-encoded segments, which can be crafted to span hundreds of megabytes. Later versions with limits on header and signature segment sizes are not affected.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Homebrewmore threats →ghsa
mcpm
pkg:brew/mcpm
Affected versions
>=2.1.0 <2.9.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 01:56:31 UTC

Technical Analysis

Authlib's JOSE implementation accepts unbounded JWS/JWT header and signature segments, allowing a remote attacker to craft tokens with extremely large base64url-encoded header or signature segments. During token verification, Authlib decodes and parses the entire input before rejecting it, causing high CPU and memory usage that can exhaust service capacity and cause denial of service. The vulnerability affects Authlib versions up to 1.6.3. The issue is mitigated in later versions by enforcing a 256 KB limit on decoded header and signature segment sizes.

Potential Impact

An unauthenticated network attacker can submit malicious JWS/JWT tokens with oversized header or signature segments, causing the Authlib verification process to consume excessive CPU and memory resources. This can lead to denial of service by exhausting the target service's capacity. The CVSS v3.1 score is 7.5 (High), reflecting the ease of attack and impact on availability without affecting confidentiality or integrity.

Mitigation Recommendations

A patch is available that enforces maximum decoded size limits of 256 KB on JWS/JWT header and signature segments in Authlib. Users should upgrade to a patched release immediately. As additional defense, inputs exceeding a few kilobytes should be rejected at proxy or WAF layers, and rate limiting should be applied to verification endpoints. Temporary workarounds include enforcing input size limits before token processing and applying application-level throttling to reduce amplification risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-mcpm-CVE-2025-61920
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6aac8e4a55bf5e2cf549141d

Added to database: 09/18/2026, 01:05:14 UTC

Last enriched: 09/18/2026, 01:56:31 UTC

Last updated: 09/18/2026, 02:07:44 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses