Search CVE reports


Toggle filters

1 – 3 of 3 results


CVE-2024-53861

Medium priority
Not affected

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim...

1 affected package

pyjwt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
pyjwt Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-29217

Medium priority

Some fixes available 3 of 4

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the...

1 affected package

pyjwt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
pyjwt Fixed Fixed Fixed Not affected
Show less packages

CVE-2017-11424

Medium priority
Fixed

In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the...

1 affected package

pyjwt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
pyjwt Fixed
Show less packages