CVE-2026-39373 | latchset jwcrypto up to 1.5.6 JWE data amplification (GHSA-fjrm-76x2-c4q4 / EUVD-2026-19911)
A vulnerability was found in latchset jwcrypto up to 1.5.6. It has been declared as problematic. This impacts an unknown function of the component JWE Handler. The manipulation results in highly compressed data.
This vulnerability is cataloged as CVE-2026-39373. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.