CVE-2025-53864
MediumAdvisory
Published 11 Jul 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.8
- base score, highest
- EPSS
- 0.008
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 169
- of 17,781 indexed, latest versions
- Container images
- 177
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Carried by container images the latest versions of 169 of 17,781 indexed charts deploy, on 177 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nimbus-jose-jwtmaven | 3.1.2, 3.9, 4.41.1, 4.41.2+35 more | 9.37.4, 10.0.2 | 177 |
- OSV records
- GHSA-xwmg-2g98-w7v9
Charts affected
169 by stars
Container images carrying it
177 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 52f376e64b9b | nimbus-jose-jwt | 9.37.4 | 4 |
| apache/ | 0bd3b25c4be4 | nimbus-jose-jwt | 9.37.4 | 3 |
| gchq/ | 5ec58edbb2db | nimbus-jose-jwt | 9.37.4 | 3 |
| mockserver/ | 0f9ef78c9489 | nimbus-jose-jwt | 9.37.4 | 3 |
| provectuslabs/ | 8f2ff02d64b0 | nimbus-jose-jwt | 9.37.4 | 3 |
| apache/ | 0116fb802786 | nimbus-jose-jwt | 9.37.4 | 2 |
| apache/ | a83cf1980609 | nimbus-jose-jwt | 9.37.4 | 2 |
| apache/ | 7cdfd8deec92 | nimbus-jose-jwt | 9.37.4 | 2 |
| danisla/ | 255ba2dd739b | nimbus-jose-jwt | 9.37.4 | 2 |
| dependencytrack/ | 485ac0952c02 | nimbus-jose-jwt | 9.37.4 | 2 |
| hazelcast/ | 5dd5d31c7a06 | nimbus-jose-jwt | 10.0.2 | 2 |
| hazelcast/ | 991ddb27c251 | nimbus-jose-jwt | 10.0.2 | 2 |
| hookiesolutions/ | 0629694246ba | nimbus-jose-jwt | 9.37.4 | 2 |
| inaccel/ | 8c53744ed70b | nimbus-jose-jwt | 9.37.4 | 2 |
| library/ | 5e6ac15bf6a5 | nimbus-jose-jwt | 9.37.4 | 2 |
| opensearchproject/ | 7f6fa1efee8f | nimbus-jose-jwt | 10.0.2 | 2 |
| scorpiobroker/ | 01e11d800459 | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | 3f05a113a4be | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | 5073ceef2fa0 | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | 62dae3dd0eeb | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | a2cfcf0947fd | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | b742a53b2803 | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | b7fe27a06ff5 | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | e08036670d66 | nimbus-jose-jwt | 9.37.4 | 2 |
| scorpiobroker/ | f02e8a429a08 | nimbus-jose-jwt | 9.37.4 | 2 |
| ghcr.io/ | 896fc7b18b1b | nimbus-jose-jwt | 9.37.4 | 2 |
| quay.io/ | 02f6f143fc6d | nimbus-jose-jwt | 9.37.4 | 2 |
| quay.io/ | ac434a48ac2b | nimbus-jose-jwt | 9.37.4 | 2 |
| 1dev/ | cd5b12fe5471 | nimbus-jose-jwt | 9.37.4 | 1 |
| 2martens/ | ba2c3040dab0 | nimbus-jose-jwt | 9.37.4 | 1 |
| 5200710/ | 092d3088a5fb | nimbus-jose-jwt | 9.37.4 | 1 |
| 5200710/ | e34ab066d2ed | nimbus-jose-jwt | 9.37.4 | 1 |
| adityaprasadpathak/ | 7e3b9777362c | nimbus-jose-jwt | 9.37.4 | 1 |
| ahmetfurkandemir/ | 142231a0b8b7 | nimbus-jose-jwt | 10.0.2 | 1 |
| aktosecurity/ | bcd7382c9c1b | nimbus-jose-jwt | 9.37.4 | 1 |
| aktosecurity/ | 274042ed7a53 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 1f96558fd292 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 0cef139b6bf1 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 80136ae753ee | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | af361b20bec0 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 8647309f95d1 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | afa47bf1692a | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 090b7f87ec7f | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 63b8e3e40742 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 974efa2f21da | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 76c176e8a0e4 | nimbus-jose-jwt | 9.37.4 | 1 |
| apache/ | 1bd5756f6273 | nimbus-jose-jwt | 9.37.4 | 1 |
| assistiot/ | 4228b7a8ef40 | nimbus-jose-jwt | 9.37.4 | 1 |
| assistiot/ | c8b6c7eaa0cd | nimbus-jose-jwt | 9.37.4 | 1 |
| atlassian/ | 3b9222ab32ef | nimbus-jose-jwt | 9.37.4 | 1 |