Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

github логотип

GHSA-xgmm-8j9v-c9wx

около 2 месяцев назад

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2026-48526

2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-48526

2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-48526

2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2026-48526

9 дней назад

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

EPSS: Низкий
debian логотип

CVE-2026-48526

2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, w ...

CVSS3: 7.4
EPSS: Низкий
rocky логотип

RLSA-2026:26206

около 2 месяцев назад

Important: fence-agents security update

EPSS: Низкий
rocky логотип

RLSA-2026:25902

около 2 месяцев назад

Important: fence-agents security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26206

около 1 месяца назад

ELSA-2026-26206: fence-agents security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-25902

17 дней назад

ELSA-2026-25902: fence-agents security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2627-1

около 1 месяца назад

Security update for python-PyJWT

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21095-1

около 1 месяца назад

Security update for python-PyJWT

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2626-1

около 1 месяца назад

Security update for python-PyJWT

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgmm-8j9v-c9wx

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

CVSS3: 7.4
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-48526

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

0%
Низкий
9 дней назад
debian логотип
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, w ...

CVSS3: 7.4
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:26206

Important: fence-agents security update

0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:25902

Important: fence-agents security update

0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-26206

ELSA-2026-26206: fence-agents security update (IMPORTANT)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-25902

ELSA-2026-25902: fence-agents security update (IMPORTANT)

0%
Низкий
17 дней назад
suse-cvrf логотип
SUSE-SU-2026:2627-1

Security update for python-PyJWT

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21095-1

Security update for python-PyJWT

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2626-1

Security update for python-PyJWT

около 1 месяца назад

Уязвимостей на страницу