The fact
The attack exploits PBES2 encryption to cause system overload through malicious JWE tokens.
The flaw, analyzed on March 6, 2026, requires immediate patching for services using this dependency.
2 sources — click a link to read an article on the topic: