CVE-2026-32597
EUVD-2026-1172813.03.2026, 19:55
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyjwt_project | pyjwt | 𝑥 < 2.12.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:4.6.28-3.el8ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:2.12.1-1.el8ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:4.6.28-3.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:2.12.1-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:4.7.11-2.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:2.12.1-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:4.16.0-13.el10_1.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:4.16.0-21.el10_2.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:4.16.0-5.el10_0.9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.2.1-129.el8_10.25 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.10.0-110.el9_8.2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.10.0-98.el9_7.12 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:4.10.0-43.el9_2.21 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:4.10.0-62.el9_4.24 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:4.10.0-86.el9_6.16 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680192 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680262 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775749857 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1777394109 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1777403872 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777296732 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777391447 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777311120 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777299023 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777398576 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777387242 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777311601 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776871984 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776871985 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776872005 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776773390 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776871987 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776773505 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776938871 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1776338381 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1776343111 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1780069069 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783696512 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783616068 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783998551 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783664916 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783615385 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783664921 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783696507 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783615414 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783998585 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783664921 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783615165 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783664921 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783615432 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1778264363 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1778600187 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1782472374 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.1 | 1775169155 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.12 | 1775253092 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.15 | 1775169219 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.16 | 1779204086 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.9 | 1775169218 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 | 1780414237 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Trusted Artifact Signer 1.4 | 1775815407 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python3-PyJWT |
| ||||||||||||
| python311-PyJWT |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| fence-agents-aliyun |
| ||||
| fence-agents-all |
| ||||
| fence-agents-amt-ws |
| ||||
| fence-agents-apc |
| ||||
| fence-agents-apc-snmp |
| ||||
| fence-agents-aws |
| ||||
| fence-agents-azure-arm |
| ||||
| fence-agents-bladecenter |
| ||||
| fence-agents-brocade |
| ||||
| fence-agents-cisco-mds |
| ||||
| fence-agents-cisco-ucs |
| ||||
| fence-agents-common |
| ||||
| fence-agents-compute |
| ||||
| fence-agents-drac5 |
| ||||
| fence-agents-eaton-snmp |
| ||||
| fence-agents-emerson |
| ||||
| fence-agents-eps |
| ||||
| fence-agents-gce |
| ||||
| fence-agents-heuristics-ping |
| ||||
| fence-agents-hpblade |
| ||||
| fence-agents-ibm-powervs |
| ||||
| fence-agents-ibm-vpc |
| ||||
| fence-agents-ibmblade |
| ||||
| fence-agents-ifmib |
| ||||
| fence-agents-ilo-moonshot |
| ||||
| fence-agents-ilo-mp |
| ||||
| fence-agents-ilo-ssh |
| ||||
| fence-agents-ilo2 |
| ||||
| fence-agents-intelmodular |
| ||||
| fence-agents-ipdu |
| ||||
| fence-agents-ipmilan |
| ||||
| fence-agents-kdump |
| ||||
| fence-agents-kubevirt |
| ||||
| fence-agents-lpar |
| ||||
| fence-agents-mpath |
| ||||
| fence-agents-nutanix-ahv |
| ||||
| fence-agents-openstack |
| ||||
| fence-agents-redfish |
| ||||
| fence-agents-rhevm |
| ||||
| fence-agents-rsa |
| ||||
| fence-agents-rsb |
| ||||
| fence-agents-sbd |
| ||||
| fence-agents-scsi |
| ||||
| fence-agents-virsh |
| ||||
| fence-agents-vmware-rest |
| ||||
| fence-agents-vmware-soap |
| ||||
| fence-agents-wti |
| ||||
| fence-agents-zvm |
| ||||
| fence-virt |
| ||||
| fence-virtd |
| ||||
| fence-virtd-cpg |
| ||||
| fence-virtd-libvirt |
| ||||
| fence-virtd-multicast |
| ||||
| fence-virtd-serial |
| ||||
| fence-virtd-tcp |
| ||||
| ha-cloud-support |
|
Amazon Linux Releases
Common Weakness Enumeration
- CWE-345 - Insufficient Verification of Data AuthenticityThe software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
- CWE-347 - Improper Verification of Cryptographic SignatureThe software does not verify, or incorrectly verifies, the cryptographic signature for data.
References