Mcpm: Authlib is vulnerable to Denial of Service via Oversized JOSE Segments (CVE-2025-61920)
Authlib versions up to 1.6.3 have a vulnerability in their JOSE implementation where oversized JWS/JWT header or signature segments can cause excessive CPU and memory consumption during verification, leading to denial of service. The vulnerability arises because the library accepts unbounded base64url-encoded segments, which can be crafted to span hundreds of megabytes. Later versions with limits on header and signature segment sizes are not affected.
AI Analysis
Technical Summary
Authlib's JOSE implementation accepts unbounded JWS/JWT header and signature segments, allowing a remote attacker to craft tokens with extremely large base64url-encoded header or signature segments. During token verification, Authlib decodes and parses the entire input before rejecting it, causing high CPU and memory usage that can exhaust service capacity and cause denial of service. The vulnerability affects Authlib versions up to 1.6.3. The issue is mitigated in later versions by enforcing a 256 KB limit on decoded header and signature segment sizes.
Potential Impact
An unauthenticated network attacker can submit malicious JWS/JWT tokens with oversized header or signature segments, causing the Authlib verification process to consume excessive CPU and memory resources. This can lead to denial of service by exhausting the target service's capacity. The CVSS v3.1 score is 7.5 (High), reflecting the ease of attack and impact on availability without affecting confidentiality or integrity.
Mitigation Recommendations
A patch is available that enforces maximum decoded size limits of 256 KB on JWS/JWT header and signature segments in Authlib. Users should upgrade to a patched release immediately. As additional defense, inputs exceeding a few kilobytes should be rejected at proxy or WAF layers, and rate limiting should be applied to verification endpoints. Temporary workarounds include enforcing input size limits before token processing and applying application-level throttling to reduce amplification risk.
Mcpm: Authlib is vulnerable to Denial of Service via Oversized JOSE Segments (CVE-2025-61920)
Description
Authlib versions up to 1.6.3 have a vulnerability in their JOSE implementation where oversized JWS/JWT header or signature segments can cause excessive CPU and memory consumption during verification, leading to denial of service. The vulnerability arises because the library accepts unbounded base64url-encoded segments, which can be crafted to span hundreds of megabytes. Later versions with limits on header and signature segment sizes are not affected.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Authlib's JOSE implementation accepts unbounded JWS/JWT header and signature segments, allowing a remote attacker to craft tokens with extremely large base64url-encoded header or signature segments. During token verification, Authlib decodes and parses the entire input before rejecting it, causing high CPU and memory usage that can exhaust service capacity and cause denial of service. The vulnerability affects Authlib versions up to 1.6.3. The issue is mitigated in later versions by enforcing a 256 KB limit on decoded header and signature segment sizes.
Potential Impact
An unauthenticated network attacker can submit malicious JWS/JWT tokens with oversized header or signature segments, causing the Authlib verification process to consume excessive CPU and memory resources. This can lead to denial of service by exhausting the target service's capacity. The CVSS v3.1 score is 7.5 (High), reflecting the ease of attack and impact on availability without affecting confidentiality or integrity.
Mitigation Recommendations
A patch is available that enforces maximum decoded size limits of 256 KB on JWS/JWT header and signature segments in Authlib. Users should upgrade to a patched release immediately. As additional defense, inputs exceeding a few kilobytes should be rejected at proxy or WAF layers, and rate limiting should be applied to verification endpoints. Temporary workarounds include enforcing input size limits before token processing and applying application-level throttling to reduce amplification risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-mcpm-CVE-2025-61920
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6aac8e4a55bf5e2cf549141d
Added to database: 09/18/2026, 01:05:14 UTC
Last enriched: 09/18/2026, 01:56:31 UTC
Last updated: 09/18/2026, 02:07:44 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.