Skip to content

Conversation

@dnastack-renovate
Copy link
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
com.nimbusds:nimbus-jose-jwt 9.48 -> 10.0.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-53864

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.


Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

CVE-2025-53864 / GHSA-xwmg-2g98-w7v9

More information

Details

Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

Severity

  • CVSS Score: 5.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

connect2id/nimbus-jose-jwt (com.nimbusds:nimbus-jose-jwt)

v10.0.2

Compare Source

v10.0.1

Compare Source

v10.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@platform-automation-dnastack

@github-actions
Copy link

github-actions bot commented Oct 1, 2025

Test Results

48 tests  ±0   48 ✅ ±0   12s ⏱️ -1s
 5 suites ±0    0 💤 ±0 
 5 files   ±0    0 ❌ ±0 

Results for commit 1ec8878. ± Comparison against base commit 4be69b1.

♻️ This comment has been updated with latest results.

@dnastack-renovate dnastack-renovate bot force-pushed the renovate/major-version.nimbus branch from 5f6e898 to 168a185 Compare October 1, 2025 12:23
@dnastack-renovate dnastack-renovate bot force-pushed the renovate/major-version.nimbus branch from 168a185 to 1ec8878 Compare October 2, 2025 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants