[Git][security-tracker-team/security-tracker][master] pyjwt fixed in sid
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Jul 2 15:49:13 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a8e94e1c by Moritz Muehlenhoff at 2026-07-02T16:48:46+02:00
pyjwt fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -24862,23 +24862,23 @@ CVE-2026-48735 (pypdf is a free and open-source pure-python PDF library. Prior t
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-wjqc-6w8f-h24c
NOTE: https://github.com/py-pdf/pypdf/pull/3796
CVE-2026-48526 (PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, w ...)
- - pyjwt <unfixed> (bug #1138191)
+ - pyjwt 2.13.0-1 (bug #1138191)
NOTE: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx
NOTE: https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 (2.13.0)
CVE-2026-48525 (PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12 ...)
- - pyjwt <unfixed> (bug #1138191)
+ - pyjwt 2.13.0-1 (bug #1138191)
NOTE: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39
NOTE: https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 (2.13.0)
CVE-2026-48524 (PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, P ...)
- - pyjwt <unfixed> (bug #1138191)
+ - pyjwt 2.13.0-1 (bug #1138191)
NOTE: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8
NOTE: https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 (2.13.0)
CVE-2026-48523 (PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12 ...)
- - pyjwt <unfixed> (bug #1138191)
+ - pyjwt 2.13.0-1 (bug #1138191)
NOTE: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f
NOTE: https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 (2.13.0)
CVE-2026-48522 (PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, P ...)
- - pyjwt <unfixed> (bug #1138191)
+ - pyjwt 2.13.0-1 (bug #1138191)
NOTE: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4
NOTE: https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 (2.13.0)
CVE-2026-48156 (pypdf is a free and open-source pure-python PDF library. Prior to 6.12 ...)
@@ -157202,7 +157202,7 @@ CVE-2025-54657
CVE-2025-4523 (The IDonate \u2013 Blood Donation, Request And Donor Management System ...)
NOT-FOR-US: WordPress plugin
CVE-2025-45768 (pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is ...)
- - pyjwt <unfixed> (bug #1110318; unimportant)
+ - pyjwt 2.13.0-1 (bug #1110318; unimportant)
NOTE: disputed upstream, negligible security impact, cf.
NOTE: https://github.com/jpadilla/pyjwt/issues/1080#issuecomment-3164212492
NOTE: https://github.com/advisories/GHSA-xpf8-484v-j9w6
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8e94e1cb07f2c96e13173769f2d71af1425c58c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8e94e1cb07f2c96e13173769f2d71af1425c58c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/c618829f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list