Pyjwt Project

Pyjwt

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.09.2026 21:15:12
  • Zuletzt bearbeitet 08.10.2026 13:13:53

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same ma...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 28.09.2026 21:17:15
  • Zuletzt bearbeitet 06.10.2026 18:17:51

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs wh...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 28.09.2026 21:17:15
  • Zuletzt bearbeitet 06.10.2026 18:25:21

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contai...

  • EPSS 0.18%
  • Veröffentlicht 28.09.2026 21:17:15
  • Zuletzt bearbeitet 06.10.2026 18:29:42

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs wh...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 28.09.2026 21:17:15
  • Zuletzt bearbeitet 06.10.2026 18:34:24

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON....

Exploit
  • EPSS 0.18%
  • Veröffentlicht 28.09.2026 21:17:15
  • Zuletzt bearbeitet 06.10.2026 18:36:16

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an applicati...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 28.09.2026 21:17:14
  • Zuletzt bearbeitet 07.10.2026 20:57:14

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loa...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 28.09.2026 21:17:14
  • Zuletzt bearbeitet 06.10.2026 18:46:19

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers witho...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 28.09.2026 21:17:14
  • Zuletzt bearbeitet 06.10.2026 18:54:08

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL ch...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 28.09.2026 21:17:14
  • Zuletzt bearbeitet 07.10.2026 20:25:03

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an applic...