Amazon Linux 2023 — python-jwcrypto — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read • Source: Amazon Linux advisory ALAS2023-2026-1590 Related CVEs: CVE-2024-28102 CVE-2026-39373 Upstream summary: JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE […]