CVE-2025-53864: Medium severity Connect2id Nimbus JOSE + JWT vulnerability
Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.
Other sources
Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53864?
CVE-2025-53864 is classified as a denial of service vulnerability.
How do I fix CVE-2025-53864?
To mitigate CVE-2025-53864, upgrade Connect2id Nimbus JOSE + JWT to version 10.0.2 or later.
What kind of attack does CVE-2025-53864 allow?
CVE-2025-53864 allows remote attackers to cause a denial of service through a deeply nested JSON object in a JWT claim set.
Which versions of Connect2id Nimbus JOSE + JWT are affected by CVE-2025-53864?
CVE-2025-53864 affects versions prior to 10.0.2 of Connect2id Nimbus JOSE + JWT.
Is CVE-2025-53864 related to Gson 2.11.0 issues?
CVE-2025-53864 is independent of the Gson 2.11.0 issue, as the Connect2id product could have implemented additional checks.