UbuntuUpdates.org

Package "python3-jwt"

Name: python3-jwt

Description:

Python 3 implementation of JSON Web Token

Latest version: 2.10.1-4ubuntu1.1
Release: resolute (26.04)
Level: security
Repository: main
Head package: pyjwt
Homepage: https://github.com/jpadilla/pyjwt

Links


Download "python3-jwt"


Other versions of "python3-jwt" in Resolute

Repository Area Version
base main 2.10.1-4ubuntu1
updates main 2.10.1-4ubuntu1.1

Changelog

Version: 2.10.1-4ubuntu1.1 2026-09-28 03:07:27 UTC

pyjwt (2.10.1-4ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: multiple security vulnerabilities
    - debian/patches/CVE-2026-48522-to-48526.patch: Bundle security fixes and
      hardening into 2.13.0 in jwt/algorithms.py, jwt/api_jws.py,
      jwt/jwks_client.py, tests/test_algorithms.py, tests/test_api_jws.py,
      tests/test_jwks_client.py.
    - CVE-2026-48522
    - CVE-2026-48523
    - CVE-2026-48524
    - CVE-2026-48525
    - CVE-2026-48526

 -- Shishir Subedi Mon, 21 Sep 2026 12:40:06 +0545

CVE-2026-48522 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which u
CVE-2026-48523 PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or j
CVE-2026-48524 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint f
CVE-2026-48525 PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64
CVE-2026-48526 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric



About   -   Send Feedback to @ubuntu_updates