Known vulnerabilities in pyjwt

Software: pyjwt
Software CPE: cpe:2.3:a:jpadilla:pyjwt:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting pyjwt pyjwt is affected by 10 known vulnerabilities: 1 high, 4 medium, 5 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132105 - Improper Verification of Cryptographic Signature
CVE-2026-48526
CWE-347 Medium
No
No
2.13.0 21.05.2026 SB2026052164
SB2026061959
SB20260625183
and 1 more
#VU132104 - Resource exhaustion
CVE-2026-48525
CWE-400 Medium
No
No
2.13.0 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU132103 - Improper Cleanup on Thrown Exception
CVE-2026-48524
CWE-460 Low
No
No
2.13.0 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 2 more
#VU132101 - Server-Side Request Forgery (SSRF)
CVE-2026-48522
CWE-918 Low
No
No
2.13.0 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU132102 - Externally Controlled Reference to a Resource in Another Sphere
CWE-610 Low
No
No
2.13.0 21.05.2026 SB2026052164
#VU132100 - Improper Verification of Cryptographic Signature
CVE-2026-48523
CWE-347 Low
No
No
2.13.0 21.05.2026 SB2026052164
SB2026061959
SB2026061972
and 3 more
#VU128143 - Insufficient Verification of Data Authenticity
CVE-2026-32597
CWE-345 Medium
No
No
2.12.0 27.04.2026 SB20260427100
SB20260427131
SB20260427132
and 12 more
#VU115711 - Missing Encryption of Sensitive Data
CVE-2025-45768
CWE-311 High
No
No
- 17.09.2025 SB2025091749
SB2025091750
SB2025092508
and 1 more
#VU103946 - Incorrect Comparison
CVE-2024-53861
CWE-697 Low
No
No
2.10.1 13.02.2025 SB2025021309
SB2025021320
SB2025082202
and 1 more
#VU63168 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-29217
CWE-327 Medium
No
No
2.4.0 13.05.2022 SB2022051319
SB2022071428
SB2022071429
and 12 more