While working on guardrails Project, I discovered a Denial of Service (DoS) vulnerability in the authlib package. The issue occurs due to unbounded JOSE segment sizes — a malicious actor can craft an oversized JWS/JWT token that consumes excessive CPU and memory during decoding and verification.
CVE Link
CVE Report