[Git][security-tracker-team/security-tracker][master] One pyjwt issue fixed in v2.11.0 upstream

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 3 20:21:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
49124418 by Salvatore Bonaccorso at 2026-07-03T21:18:26+02:00
One pyjwt issue fixed in v2.11.0 upstream

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -158384,7 +158384,7 @@ CVE-2025-54657
 CVE-2025-4523 (The IDonate \u2013 Blood Donation, Request And Donor Management System ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-45768 (pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is ...)
-	- pyjwt 2.13.0-1 (bug #1110318; unimportant)
+	- pyjwt 2.11.0-2 (bug #1110318; unimportant)
 	NOTE: disputed upstream, negligible security impact, cf.
 	NOTE: https://github.com/jpadilla/pyjwt/issues/1080#issuecomment-3164212492
 	NOTE: https://github.com/advisories/GHSA-xpf8-484v-j9w6



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/491244185a88fb13ccbef9c12c159bad2651aef1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/491244185a88fb13ccbef9c12c159bad2651aef1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260703/a5d0e30f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list