CVE-2026-33204: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33204 is an unauthenticated Denial of Service vulnerability in the SimpleJWT PHP library caused by JWE header tampering when PBES2 algorithms are used. An attacker can send a crafted JWE token with an arbitrarily large p2c (PBKDF2 iteration count) value, forcing the server to perform an excessive number of PBKDF2 iterations and exhausting CPU resources. The vulnerability affects all versions of kelvinmo/simplejwt up to and including 1.1.0, and was patched in version 1.1.1. It was published on March 18, 2026, with a CVSS v3.1 base score of 7.5 (High) (Github Advisory, SimpleJWT Advisory).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) in PBES2.php, where the decryptKey() method passes the attacker-controlled p2c header value directly to PHP's hash_pbkdf2() function without any upper-bound validation or sanity ceiling on the iteration count. Because the JWE header is processed before decryption and authentication occur, an attacker can trigger the vulnerability using a structurally invalid JWE — only the Base64URL-encoded JSON header needs to be well-formed; the remaining segments can be arbitrary data. A public proof-of-concept demonstrates crafting a JWE with p2c set to 409,123,223,136 (over 400 billion iterations), which blocks the PHP request worker until the execution timeout is reached (SimpleJWT Advisory, Github Advisory).

Impact

Successful exploitation results in complete availability loss for the affected application — repeated crafted requests exhaust server CPU resources and block request workers, rendering the service unavailable to legitimate users. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Any PHP application that calls JWE::decrypt() on attacker-supplied JWE tokens using PBES2 algorithms (PBES2-HS256+A128KW, PBES2-HS384+A192KW, or PBES2-HS512+A256KW) is affected (SimpleJWT Advisory).

Exploitability

A working proof-of-concept exploit with concrete reproduction steps and a crafted JWE payload is publicly available in the GitHub Security Advisory (SimpleJWT Advisory). The attack requires no authentication, no privileges, and no user interaction, making it trivially exploitable by any network-accessible attacker. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.044–0.045%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).

Exploitation steps

  1. Identify target: Locate a PHP application that uses kelvinmo/simplejwt <= 1.1.0 and exposes an endpoint that calls JWE::decrypt() on user-supplied input with a PBES2 algorithm (e.g., PBES2-HS256+A128KW).
  2. Craft malicious JWE header: Construct a JWE header JSON with an extremely large p2c value, for example:
{"alg": "PBES2-HS256+A128KW", "enc": "A128CBC-HS256", "p2s": "blablabla", "p2c": 409123223136}
  1. Encode the header: Base64URL-encode the JSON header. The remaining JWE segments (encrypted key, IV, ciphertext, tag) can be arbitrary placeholder values (e.g., bla).
  2. Assemble the JWE: Combine the encoded header with dummy segments: eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJlbmMiOiJBMTI4Q0JDLUhTMjU2IiwicDJzIjoiYmxhYmxhYmxhIiwicDJjIjo0MDkxMjMyMjMxMzZ9.bla.bla.bla.bla
  3. Send the request: Submit the crafted JWE to the target endpoint:
curl --path-as-is -i -s -k -X 'GET' \
  -H 'Host: <target>' \
  'http://<target>/decrypt?s=eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJlbmMiOiJBMTI4Q0JDLUhTMjU2IiwicDJzIjoiYmxhYmxhYmxhIiwicDJjIjo0MDkxMjMyMjMxMzZ9.bla.bla.bla.bla'
  1. Achieve DoS: The server worker blocks while computing PBKDF2 with 400+ billion iterations, consuming CPU until the PHP execution timeout is reached. Repeat requests to sustain the denial of service (SimpleJWT Advisory).

Indicators of compromise

  • Network: Repeated HTTP GET or POST requests to JWE decryption endpoints (e.g., /decrypt) with unusually long or structured query parameters containing Base64URL-encoded JWE tokens; high request rate from a single or rotating source IP targeting token processing endpoints.
  • Logs: PHP error logs showing Fatal error: Maximum execution time of 30+2 seconds exceeded in PBES2.php; web server access logs with repeated requests to JWE-handling endpoints returning timeouts or 500 errors.
  • Process/System: Sustained high CPU utilization on the PHP-FPM or web server process with no corresponding legitimate traffic spike; PHP worker processes stuck or timing out at abnormally high rates.
  • Application: Increased rate of InvalidTokenException or timeout errors from the SimpleJWT library in application logs (SimpleJWT Advisory).

Mitigation and workarounds

Upgrade kelvinmo/simplejwt to version 1.1.1, which adds validation of the p2c parameter in the PBES2 implementation to enforce a maximum iteration count (SimpleJWT Release). As a temporary workaround prior to patching, implement rate limiting on endpoints that process JWE tokens, and consider adding application-level validation to reject p2c values exceeding a reasonable threshold (e.g., the RFC 7518 recommended minimum of 1000, with a practical ceiling). Monitoring CPU consumption during token processing and setting PHP execution time limits can reduce the impact of individual requests but will not prevent resource exhaustion from repeated attacks (Github Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Edoardo Ottavianelli (@edoardottt), who provided a detailed proof-of-concept in the GitHub Security Advisory (SimpleJWT Advisory). Red Hat tracked the issue via Bugzilla (Bug 2449822) and assigned it medium severity for their product ecosystem (bugzilla.redhat.com). Social media activity was limited, with brief mentions on Mastodon and Bluesky shortly after disclosure, reflecting the niche scope of the affected library.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management