-
-
Notifications
You must be signed in to change notification settings - Fork 715
Open
Description
Hi Team,
The pyJWT version 2.10.1 been reported as a high vulnerability on NVD database(CVE-2025-45768) and in blackduck as well(BDSA-2025-8013). Since this is a high severity can you please please look into this issue and if possible provide us a tentative date on the new releases.
Issue description:
Pyjwt is vulnerable to weak encryption due to insufficient HMAC and RSA key length in the JSON web signature (JWS) implementation. A remote attacker could exploit this Vulnerability in order to manipulate data or gain unauthorized access.
mgmm13, Bonn-Lu, JuliOnGit, SiyaSecOps, seifrajhi and 7 moredcierco, sschwein, costinchen, KingofGnome, rayluo and 5 more
Metadata
Metadata
Assignees
Labels
No labels