Skip to content

Security Vulnerability #1080

@nishanth77

Description

@nishanth77

Hi Team,
The pyJWT version 2.10.1 been reported as a high vulnerability on NVD database(CVE-2025-45768) and in blackduck as well(BDSA-2025-8013). Since this is a high severity can you please please look into this issue and if possible provide us a tentative date on the new releases.

Issue description:
Pyjwt is vulnerable to weak encryption due to insufficient HMAC and RSA key length in the JSON web signature (JWS) implementation. A remote attacker could exploit this Vulnerability in order to manipulate data or gain unauthorized access.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions