GHSA-f6vf-pq8c-69m4 · Severity: critical · Ecosystem: maven — Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Conclusion & alert: CVE-2019-17195 is rated High Risk (68.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 4.27%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-27 | 6.27% | 4.27% | -2.00% |
| 2 | 2026-04-26 | 3.01% | 6.27% | +3.26% |
| 3 | 2026-03-18 | — | 3.01% | — |
Full EPSS history (33 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-f6vf-pq8c-69m4 · Severity: critical · Ecosystem: maven — Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-17195 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| connect2id | nimbus_jose\+jwt | < 7.9 | cpe:2.3:a:connect2id:nimbus_jose\+jwt:*:*:*:*:*:*:*:* |
| apache | hadoop | 3.2.1 | cpe:2.3:a:apache:hadoop:3.2.1:-:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 | cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:* |
| oracle | communications_pricing_design_center | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | data_integrator | 12.2.1.4.0 | cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_base_platform | 13.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* |
| oracle | healthcare_data_repository | 8.1.0 | cpe:2.3:a:oracle:healthcare_data_repository:8.1.0:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | >= 11.0, <= 11.3.1 | cpe:2.3:a:oracle:insurance_policy_administration:*:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_orchestrator | <= 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | <= 9.2.5.3 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.59 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
| oracle | policy_automation | >= 12.2.0, <= 12.2.22 | cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 18.8.0, <= 18.8.11 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | 19.12.0 | cpe:2.3:a:oracle:primavera_gateway:19.12.0:*:*:*:*:*:*:* |
| oracle | solaris_cluster | 4.0 | cpe:2.3:a:oracle:solaris_cluster:4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.3.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.4.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* |