Logo
componentpython3-pyjwt
Name
python3-pyjwt
Version
2.8.0
Type
library
Description
JSON Web Token implementation in Python
Licenses
MIT
PURL
-
CPE
cpe:2.3:*:*:python3-pyjwt:2.8.0:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.3.0
master
2.13.0

Patches#


#
Title
Author
Resolve
1
Merge commit from fork
=?UTF-8?q?Jos=C3=A9=20Padilla?= <jpadilla@webapplicate.com>
CVE-2026-32597

Vulnerabilities#


Name
Analysis
Description
Patched
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.