Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 45

Количество 45

nvd логотип

CVE-2026-32597

6 месяцев назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-32597

около 2 месяцев назад

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-32597

6 месяцев назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-30922

6 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-30922

6 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-30922

6 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-30922

6 месяцев назад

pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-30922

6 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pya ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20431-1

6 месяцев назад

Security update for python-PyJWT

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1400-1

5 месяцев назад

Security update for python-PyJWT

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1389-1

5 месяцев назад

Security update for python-PyJWT

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1199-1

5 месяцев назад

Security update for python-PyJWT

EPSS: Низкий
github логотип

GHSA-752w-5fwx-jx9f

6 месяцев назад

PyJWT accepts unknown `crit` header extensions

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-04360

6 месяцев назад

Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20418-1

6 месяцев назад

Security update for python-pyasn1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1158-1

6 месяцев назад

Security update for python-pyasn1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1076-1

6 месяцев назад

Security update for python-pyasn1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1075-1

6 месяцев назад

Security update for python-pyasn1

EPSS: Низкий
redos логотип

ROS-20260420-80-0033

5 месяцев назад

Уязвимость python-pyasn1

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:13917

4 месяца назад

Important: fence-agents security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-32597

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-32597

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-32597

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-30922

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-30922

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-30922

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-30922

pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-30922

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pya ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20431-1

Security update for python-PyJWT

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1400-1

Security update for python-PyJWT

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1389-1

Security update for python-PyJWT

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1199-1

Security update for python-PyJWT

0%
Низкий
5 месяцев назад
github логотип
GHSA-752w-5fwx-jx9f

PyJWT accepts unknown `crit` header extensions

CVSS3: 7.5
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-04360

Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20418-1

Security update for python-pyasn1

1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1158-1

Security update for python-pyasn1

1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1076-1

Security update for python-pyasn1

1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1075-1

Security update for python-pyasn1

1%
Низкий
6 месяцев назад
redos логотип
ROS-20260420-80-0033

Уязвимость python-pyasn1

CVSS3: 7.5
1%
Низкий
5 месяцев назад
rocky логотип
RLSA-2026:13917

Important: fence-agents security update

1%
Низкий
4 месяца назад

Уязвимостей на страницу