Skip to content

[GHSA-xwmg-2g98-w7v9] Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON - #9087

Open
tal-sealsecurity wants to merge 1 commit into
tal-sealsecurity/advisory-improvement-9087from
tal-sealsecurity-GHSA-xwmg-2g98-w7v9
Open

[GHSA-xwmg-2g98-w7v9] Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON#9087
tal-sealsecurity wants to merge 1 commit into
tal-sealsecurity/advisory-improvement-9087from
tal-sealsecurity-GHSA-xwmg-2g98-w7v9

Conversation

@tal-sealsecurity

Copy link
Copy Markdown

Updates

  • Description
  • Summary

Comments
I am submitting a correction regarding the technical details and attribution of CVE-2025-53864. The official NVD description contains a note stating that this vulnerability is independent of the underlying JSON parser limits. Code analysis of the official patches proves this note is factually incorrect.

The current advisory states:

"NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson."

this is not actually a vuln in the codebase of nimbus but a vuln in its dependency

@github-actions
github-actions Bot changed the base branch from main to tal-sealsecurity/advisory-improvement-9087 August 12, 2026 10:44
@JonathanLEvans

Copy link
Copy Markdown

Hi @tal-sealsecurity,

GitHub is not the issuer of the CVE. If you want it updated, then you should contact MITRE via their form.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants