[From nobody Tue Jun 30 19:19:18 2026
Received: (at 1133006-close) by bugs.debian.org; 30 Jun 2026 18:17:11 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,
 HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,USER_IN_DKIM_WELCOMELIST
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 85; hammy, 150; neutral, 132; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:54930)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wed1D-006n7L-04 for 1133006-close@bugs.debian.org;
 Tue, 30 Jun 2026 18:17:11 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wed1C-00GQnu-33 for 1133006-close@bugs.debian.org;
 Tue, 30 Jun 2026 18:17:10 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=kRNcDb+4qU5CKS0epkiaQEg6j5uLrV7YSFUmu379T34=; b=SEqzFGTxIVOPhTDhADioQj+xAm
 6O6ebmZUOuYSi9x1hBZKnbxKDLERDjpQlnl8Zn4tZKrMmAPE3VhM0pvaPYo/kIyYCpTAp6/mvEqq8
 b3LexpGzEPTB7u0XX/ZX1J1n0ye3YFIU7JZxNxhOfOfGJiprqGq4wZvtTR6GHyQgRMXQzFGk30v3T
 rCcthfj7cdmi2NRYv1zvZiEu//qMfmstam4553NXqwvNpgNyFI5oBDkhaZwYZsN2KhUNXef4FZoKN
 o5SfvnpaCJPHhngePV1ygSlza4G9OpI0u9uoLtXXUBNxZqRIMQJV9hvAlQ8/NLAqtOSU7JSB4s+KC
 5frMbD7Q==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wed1C-00000009bci-0Tul; Tue, 30 Jun 2026 18:17:10 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Adrian Bunk &lt;bunk@debian.org&gt;
To: 1133006-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: python-jwcrypto
Debian: DAK
Debian-Changes: python-jwcrypto_1.5.6-1.1~deb13u1_source.changes
Debian-Source: python-jwcrypto
Debian-Version: 1.5.6-1.1~deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1133006: fixed in python-jwcrypto 1.5.6-1.1~deb13u1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============1709143005447050101==&quot;
Message-Id: &lt;E1wed1C-00000009bci-0Tul@fasolo.debian.org&gt;
Date: Tue, 30 Jun 2026 18:17:10 +0000

--===============1709143005447050101==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: python-jwcrypto
Source-Version: 1.5.6-1.1~deb13u1
Done: Adrian Bunk &lt;bunk@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
python-jwcrypto, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1133006@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk &lt;bunk@debian.org&gt; (supplier of updated python-jwcrypto package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 27 Jun 2026 21:49:49 +0300
Source: python-jwcrypto
Architecture: source
Version: 1.5.6-1.1~deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian FreeIPA Team &lt;pkg-freeipa-devel@alioth-lists.debian.net&gt;
Changed-By: Adrian Bunk &lt;bunk@debian.org&gt;
Closes: 1133006
Changes:
 python-jwcrypto (1.5.6-1.1~deb13u1) trixie; urgency=3Dmedium
 .
   * Non-maintainer upload.
   * Rebuild for trixie.
 .
 python-jwcrypto (1.5.6-1.1) unstable; urgency=3Dmedium
 .
   * Non-maintainer upload.
   * CVE-2026-39373: JWT bomb Attack in deserialize (Closes: #1133006)
Checksums-Sha1:
 eae0a8d7c23254a9ea68933c2129ea9572a949bb 2158 python-jwcrypto_1.5.6-1.1~deb1=
3u1.dsc
 9cddb10e70995a4dd4d6285ece1ccd1956fe5767 97053 python-jwcrypto_1.5.6.orig.ta=
r.gz
 98332c968837f3e118d9b67b1a0ecd8a70fa6aca 4668 python-jwcrypto_1.5.6-1.1~deb1=
3u1.debian.tar.xz
Checksums-Sha256:
 fe3855280407f63ebcf115c3714620146e1e08242dc0801230e9a48254f9972e 2158 python=
-jwcrypto_1.5.6-1.1~deb13u1.dsc
 14f0673131e3612cdef22c81b84db4c32a9ee4d94c0053579c92e3af613ab51f 97053 pytho=
n-jwcrypto_1.5.6.orig.tar.gz
 3a1b14d9b88cadb3ac612b7e28a31cad69546a480b92ce87b9a69ae31f5623a0 4668 python=
-jwcrypto_1.5.6-1.1~deb13u1.debian.tar.xz
Files:
 72a3e75797c82df377b1790f93ab7a45 2158 python optional python-jwcrypto_1.5.6-=
1.1~deb13u1.dsc
 0294fcb15774bec9201c03203c9f7feb 97053 python optional python-jwcrypto_1.5.6=
.orig.tar.gz
 3ba3a5f4ced02b3c4019aec24e33e121 4668 python optional python-jwcrypto_1.5.6-=
1.1~deb13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmpAHcAACgkQiNJCh6LY
mLE55hAAhdX9dM2Yd5ffYfds9qt3U6WlKF+DrMbF3eW5qUxY4om+A9hn695pklYi
XPaa7muEYvaRVebhBUP2KKnK5/DTpt2TGcH8+l9jrRhLy/sxrFHtFdMwkmf6CtE9
bErVfCNf941k3J4zqX7DO9VXIC4n6PkggC7hhci7zf2+EmxyiDcRHAimSucc1XRA
Cl8tL8IMvs/tIuMaMIZcrywMWiLfC8+Ubqv0QHR/VJFME6l0L+57lNGq1+m/7cxo
kINEo67aZ/K690SWWT85K3/L+AVD30vQYmuX5ELgpReplK9bJl6Cou6G4yAg4KV/
JxUHs3KKDeaCKTQImhFjUh8oPCTguriQH3vi+QPzhZ1oNC5OAT5vpK3vttW7+LSz
igy1F7S6WCylpxMXUlpjby/5ObseAfYiOc/k7DaohfATwY9UV377k8EYwz6HEltC
Y9Eq7slgezNNEd8v8q315Mp674mKySTsTcmytpGCieZwn3DIqPzyhjoPwc/C7AaD
oZRmKG3855KIH/ORXscfDxDdDoWi8elCMRA5USE3YXa6PmFzWJZgsfs68f+U54GG
JNXzcliwK2CbeOgVi62on8BjWhPcOQl3mZ7IaW9hgehKBAjHKlHEWstT4PMmBQ/L
T0zMtMnKFlvSAWLj+3wIsuve8zyVoVzPrhqmGxx5Hp7jn5+jZPw=3D
=3DMZGw
-----END PGP SIGNATURE-----


--===============1709143005447050101==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCakQIJgAKCRCb9qggYcy5
IX5OAP9gRUNFuk2Y44wXXTFlBErMsSskxzbTR0NbECOoiE//0QD+PlwRx6iRBvNr
SA6DizVVYnbCY8B0ygMbQwMvMH1x3Qs=
=UkJo
-----END PGP SIGNATURE-----

--===============1709143005447050101==--
]