๐Ÿ” CVE Alert

CVE-2026-33204

HIGH 7.5

SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
13th

SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.

CWE CWE-400
Vendor kelvinmo
Product simplejwt
Published Mar 20, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for kelvinmo simplejwt

Be the first to know when new high vulnerabilities affecting kelvinmo simplejwt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

kelvinmo / simplejwt
< 1.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kelvinmo/simplejwt/security/advisories/GHSA-xw36-67f8-339x github.com: https://github.com/kelvinmo/simplejwt/releases/tag/v1.1.1