[Git][security-tracker-team/security-tracker][master] Add new python-jose CVE
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 3 20:33:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
773eca39 by Salvatore Bonaccorso at 2026-09-03T21:33:20+02:00
Add new python-jose CVE
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,7 +11,9 @@ CVE-2026-85396 (rubyzip versions before 3.4.0 contain a path traversal vulnerabi
CVE-2026-85395 (UnoPim before 2.1.3 fails to include integration store, update, and ke ...)
TODO: check
CVE-2026-85394 (python-jose through 3.5.0 fails to properly validate asymmetric keys i ...)
- TODO: check
+ - python-jose <not-affected> (Incomplete fix for CVE-2024-33663 not applied)
+ NOTE: https://github.com/mpdavis/python-jose/issues/414
+ NOTE: CVE exists due to an incomplete fix for CVE-2024-33663
CVE-2026-85393 (node-forge through 1.4.0 fails to validate element count in nested Dig ...)
TODO: check
CVE-2026-85392 (Peppermint through 0.5.5 contains an authorization bypass vulnerabilit ...)
@@ -365323,6 +365325,7 @@ CVE-2024-33663 (python-jose through 3.3.0 has algorithm confusion with OpenSSH E
- python-jose <removed> (bug #1070375)
[bookworm] - python-jose <ignored> (Minor issue)
NOTE: https://github.com/mpdavis/python-jose/issues/346
+ NOTE: when fixing this issue make sure to make the fix complete to not open CVE-2026-85394
CVE-2024-33661 (Portainer before 2.20.0 allows redirects when the target is not index. ...)
NOT-FOR-US: Portainer
CVE-2024-33651 (Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/773eca3936f7ef215711f2ab8b517d0ad76bf57d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/773eca3936f7ef215711f2ab8b517d0ad76bf57d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/fb32b226/attachment.htm>
More information about the debian-security-tracker-commits
mailing list