GHSA-3w98-rrpr-fprr
HIGHCVE-2026-81875SHCParser inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure.
- Affected
- <= 5.0.0
- Fixed in
- not stated
- Weakness
- CWE-20
- Published
- 2026-09-17
- Source
- github