PT-2025-29195 · Connect2Id · Nimbus Jose+Jwt

Marcono1234

·

Published

2025-07-11

·

Updated

2026-05-18

·

CVE-2025-53864

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Connect2id Nimbus JOSE + JWT versions prior to 10.0.2
Description: The software is susceptible to a denial-of-service condition triggered by a deeply nested JSON object within a JWT claim set. This occurs due to uncontrolled recursion during JSON object processing. The issue is independent of a separate problem related to Gson 2.11.0, as the Connect2id product had the capability to validate JSON object nesting depth regardless of any limits imposed by Gson.
Recommendations: Update Connect2id Nimbus JOSE + JWT to version 10.0.2 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-DD05788
CLEANSTART-2026-GQ14179
CLEANSTART-2026-JU62349
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-VH41554
CLEANSTART-2026-WK99982
CVE-2025-53864
GHSA-XWMG-2G98-W7V9

Affected Products

Nimbus Jose+Jwt