VYPR
Vendor

jpadilla

Products
1
CVEs
21
Across products
21
Status
Private

Products

1

Recent CVEs

21
View all 21 CVEs →
  • CVE-2025-45768HigJul 31, 2025
    risk 0.46cvss 7.0epss 0.00

    pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict…

  • CVE-2026-32597HigMar 13, 2026
    risk 0.42cvss 7.5epss 0.00

    PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token…

  • CVE-2026-102273HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs when an application allows HMAC…

  • CVE-2026-102272HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public…

  • CVE-2026-102271HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric…

  • CVE-2026-102267HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced…

  • CVE-2026-102266HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with…

  • CVE-2026-48526HigMay 28, 2026
    risk 0.41cvss 7.4epss 0.00

    PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer…

  • CVE-2022-29217HigMay 24, 2022
    risk 0.41cvss 7.4epss 0.01

    PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported.…

  • CVE-2026-103001MedSep 30, 2026
    risk 0.35cvss 6.5epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or…

  • CVE-2026-102275MedSep 28, 2026
    risk 0.35cvss 6.5epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK…

  • CVE-2026-102274MedSep 28, 2026
    risk 0.31cvss 5.9epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key…

  • CVE-2026-48523MedMay 28, 2026
    risk 0.28cvss 5.4epss 0.00

    PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms…

  • CVE-2026-102265MedSep 28, 2026
    risk 0.27cvss 5.3epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result,…

  • CVE-2026-101918MedSep 28, 2026
    risk 0.27cvss 5.3epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload…

  • CVE-2026-101917MedSep 28, 2026
    risk 0.27cvss 5.3epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when unauthenticated tokens repeatedly use the…

  • CVE-2026-48525MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the…

  • CVE-2026-102269MedSep 28, 2026
    risk 0.24cvss 4.8epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a…

  • CVE-2026-102270MedSep 28, 2026
    risk 0.22cvss 4.4epss 0.00

    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As…

  • CVE-2026-48522MedMay 28, 2026
    risk 0.20cvss 4.2epss 0.00

    PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There…