[Git][security-tracker-team/security-tracker][master] new python-jwcrypto issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 17 19:43:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3849f613 by Moritz Muehlenhoff at 2026-09-17T20:42:56+02:00
new python-jwcrypto issue
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2899,7 +2899,10 @@ CVE-2026-92122 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier
CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affe ...)
NOT-FOR-US: a2ui-project a2ui
CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function validates ...)
- TODO: check
+ - python-jwcrypto <unfixed>
+ NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-pwgw-f7xr-863h
+ NOTE: https://github.com/latchset/jwcrypto/pull/398
+ NOTE: https://github.com/latchset/jwcrypto/commit/21d2a2c20dbc1201ebe0b9b2621417629f37bfcd (v1.6.1)
CVE-2026-92087 (@fastify/auth is a Fastify plugin that composes multiple authenticatio ...)
NOT-FOR-US: Fastify plugin
CVE-2026-92081 (fastify is a fast and low-overhead web framework for Node.js. In versi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3849f61358d80baac5322a608710fa0928d43f20
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3849f61358d80baac5322a608710fa0928d43f20
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/20e73d54/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list