Security Advisory

CVE-2026-33204

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-20 22:37:13
Last updated 2026-03-24 15:34:35
Assigner GitHub_M
State PUBLISHED

Description

SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via JWE header tampering when PBES2 algorithms are used. Applications that call JWE::decrypt() on attacker-controlled JWEs using PBES2 algorithms are affected. This issue has been patched in version 1.1.1.