VYPR

python-jose

by Mpdavis

CVEs (1)

  • CVE-2026-85394CriSep 3, 2026
    risk 0.59cvss 9.1epss

    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not…