Logo
vulnerabilityCVE-2026-32597
Name
CVE-2026-32597
Source
NVD ( link)Debian ( link)
Description
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-pyjwt
Patched

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
kirkstone
2.3.0
Not Affected

Resolved with patches#


python3-pyjwt (yocto:scarthgap)

#
Title
Author
Resolve
1
Merge commit from fork
=?UTF-8?q?Jos=C3=A9=20Padilla?= <jpadilla@webapplicate.com>
CVE-2026-32597