Количество 45
Количество 45
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
CVE-2026-32597
PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ...
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.
CVE-2026-30922
pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pya ...
openSUSE-SU-2026:20431-1
Security update for python-PyJWT
SUSE-SU-2026:1400-1
Security update for python-PyJWT
SUSE-SU-2026:1389-1
Security update for python-PyJWT
SUSE-SU-2026:1199-1
Security update for python-PyJWT
GHSA-752w-5fwx-jx9f
PyJWT accepts unknown `crit` header extensions
BDU:2026-04360
Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности
openSUSE-SU-2026:20418-1
Security update for python-pyasn1
SUSE-SU-2026:1158-1
Security update for python-pyasn1
SUSE-SU-2026:1076-1
Security update for python-pyasn1
SUSE-SU-2026:1075-1
Security update for python-pyasn1
ROS-20260420-80-0033
Уязвимость python-pyasn1
RLSA-2026:13917
Important: fence-agents security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, P ... | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-30922 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-30922 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-30922 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-30922 pyasn1 Vulnerable to Denial of Service via Unbounded Recursion | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-30922 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pya ... | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:20431-1 Security update for python-PyJWT | 0% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1400-1 Security update for python-PyJWT | 0% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:1389-1 Security update for python-PyJWT | 0% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:1199-1 Security update for python-PyJWT | 0% Низкий | 5 месяцев назад | ||
GHSA-752w-5fwx-jx9f PyJWT accepts unknown `crit` header extensions | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
BDU:2026-04360 Уязвимость реализации JWT в Python PyJWT, связанная с недостаточной проверкой подлинности данных, содержащих дефекты, позволяющая нарушителю обойти существующие механизмы безопасности | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:20418-1 Security update for python-pyasn1 | 1% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1158-1 Security update for python-pyasn1 | 1% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1076-1 Security update for python-pyasn1 | 1% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:1075-1 Security update for python-pyasn1 | 1% Низкий | 6 месяцев назад | ||
ROS-20260420-80-0033 Уязвимость python-pyasn1 | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
RLSA-2026:13917 Important: fence-agents security update | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу