Количество 20
Количество 20
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ...
openSUSE-SU-2026:20431-1
Security update for python-PyJWT
SUSE-SU-2026:1400-1
Security update for python-PyJWT
SUSE-SU-2026:1389-1
Security update for python-PyJWT
SUSE-SU-2026:1199-1
Security update for python-PyJWT
GHSA-752w-5fwx-jx9f
PyJWT accepts unknown `crit` header extensions
BDU:2026-04360
Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности
RLSA-2026:19138
Important: fence-agents security update
RLSA-2026:13916
Important: fence-agents security update
RLSA-2026:13672
Important: fence-agents security update
ELSA-2026-19138
ELSA-2026-19138: fence-agents security update (IMPORTANT)
ELSA-2026-13916
ELSA-2026-13916: fence-agents security update (IMPORTANT)
ELSA-2026-13672
ELSA-2026-13672: fence-agents security update (IMPORTANT)
RLSA-2026:19355
Important: fence-agents security update
RLSA-2026:12176
Important: fence-agents security update
ELSA-2026-19355
ELSA-2026-19355: fence-agents security update (IMPORTANT)
ELSA-2026-12176
ELSA-2026-12176: fence-agents security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ... | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
openSUSE-SU-2026:20431-1 Security update for python-PyJWT | 0% Низкий | 4 месяца назад | ||
SUSE-SU-2026:1400-1 Security update for python-PyJWT | 0% Низкий | 4 месяца назад | ||
SUSE-SU-2026:1389-1 Security update for python-PyJWT | 0% Низкий | 4 месяца назад | ||
SUSE-SU-2026:1199-1 Security update for python-PyJWT | 0% Низкий | 4 месяца назад | ||
GHSA-752w-5fwx-jx9f PyJWT accepts unknown `crit` header extensions | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
BDU:2026-04360 Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
RLSA-2026:19138 Important: fence-agents security update | 2 месяца назад | |||
RLSA-2026:13916 Important: fence-agents security update | 3 месяца назад | |||
RLSA-2026:13672 Important: fence-agents security update | 3 месяца назад | |||
ELSA-2026-19138 ELSA-2026-19138: fence-agents security update (IMPORTANT) | 16 дней назад | |||
ELSA-2026-13916 ELSA-2026-13916: fence-agents security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-13672 ELSA-2026-13672: fence-agents security update (IMPORTANT) | 3 месяца назад | |||
RLSA-2026:19355 Important: fence-agents security update | 2 месяца назад | |||
RLSA-2026:12176 Important: fence-agents security update | 3 месяца назад | |||
ELSA-2026-19355 ELSA-2026-19355: fence-agents security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-12176 ELSA-2026-12176: fence-agents security update (IMPORTANT) | 3 месяца назад |
Уязвимостей на страницу