{"id":"ECHO-bcfa-be1b-cafd","upstream":["GHSA-cjwg-qfpm-7377","CVE-2024-33664"],"severity":[],"modified":"2026-04-12T13:28:09.164Z","affected":[{"package":{"ecosystem":"Echo:PyPi","name":"python-jose","purl":"pkg:pypi/python-jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0+echo.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/GHSA-cjwg-qfpm-7377"},{"type":"WEB","url":"https://github.com/advisories/GHSA-cjwg-qfpm-7377"}],"withdrawn":"2026-04-12T13:28:09.164Z","summary":"Limit JWE token size and decompressed output to prevent resource exhaustion.\nBackported from https://github.com/mpdavis/python-jose/commit/8e1f521\n"}