Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:26206

Опубликовано: 17 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: fence-agents security update

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.

Security Fix(es):

  • python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
fence-agents-aliyunx86_64110.el9_8.3fence-agents-aliyun-4.10.0-110.el9_8.3.x86_64.rpm
fence-agents-allx86_64110.el9_8.3fence-agents-all-4.10.0-110.el9_8.3.x86_64.rpm
fence-agents-amt-wsnoarch110.el9_8.3fence-agents-amt-ws-4.10.0-110.el9_8.3.noarch.rpm
fence-agents-apcnoarch110.el9_8.3fence-agents-apc-4.10.0-110.el9_8.3.noarch.rpm
fence-agents-apc-snmpnoarch110.el9_8.3fence-agents-apc-snmp-4.10.0-110.el9_8.3.noarch.rpm
fence-agents-awsx86_64110.el9_8.3fence-agents-aws-4.10.0-110.el9_8.3.x86_64.rpm
fence-agents-azure-armx86_64110.el9_8.3fence-agents-azure-arm-4.10.0-110.el9_8.3.x86_64.rpm
fence-agents-bladecenternoarch110.el9_8.3fence-agents-bladecenter-4.10.0-110.el9_8.3.noarch.rpm
fence-agents-brocadenoarch110.el9_8.3fence-agents-brocade-4.10.0-110.el9_8.3.noarch.rpm
fence-agents-cisco-mdsnoarch110.el9_8.3fence-agents-cisco-mds-4.10.0-110.el9_8.3.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.4
ubuntu
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
redhat
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
nvd
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
debian
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, w ...

rocky
около 2 месяцев назад

Important: fence-agents security update