CVE-2026-48526
EUVD-2026-3291728.05.2026, 16:16
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyjwt_project | pyjwt | 𝑥 < 2.13.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:4.6.31-1.el8ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:4.6.31-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:2.13.0-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:4.7.15-2.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10 | 0:4.16.0-21.el10_2.2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:4.16.0-5.el10_0.11 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.10.0-110.el9_8.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:4.10.0-43.el9_2.23 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:4.10.0-62.el9_4.26 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:4.10.0-86.el9_6.18 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:2.13.0-1.el8pc ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:2.13.0-1.el9pc ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:2.13.0-1.el9pc ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:2.13.0-1.el9pc ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:2.13.0-1.el9pc ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1782353093 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.3 | 1782352847 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1784050598 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1784046511 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1782761510 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1782650747 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1782755166 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1782712006 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1783981617 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1783979593 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1783969139 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781118924 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781102816 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781042555 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781025813 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781030318 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1783920542 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1785378052 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1785435970 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Migration Toolkit for Applications 8.2 | 1784109883 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783024305 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1783701598 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1783010225 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.1 | 1782487717 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.12 | 1781937357 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.15 | 1784351966 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.16 | 1783955846 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.18 | 1784987273 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.9 | 1781878070 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 | 1782739344 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Trusted Artifact Signer 1.3 | 1784016554 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Trusted Artifact Signer 1.4 | 1785420425 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python3-PyJWT |
| ||||||||||||
| python311-PyJWT |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| fence-agents-aliyun |
| ||
| fence-agents-all |
| ||
| fence-agents-amt-ws |
| ||
| fence-agents-apc |
| ||
| fence-agents-apc-snmp |
| ||
| fence-agents-aws |
| ||
| fence-agents-azure-arm |
| ||
| fence-agents-bladecenter |
| ||
| fence-agents-brocade |
| ||
| fence-agents-cisco-mds |
| ||
| fence-agents-cisco-ucs |
| ||
| fence-agents-common |
| ||
| fence-agents-compute |
| ||
| fence-agents-drac5 |
| ||
| fence-agents-eaton-snmp |
| ||
| fence-agents-emerson |
| ||
| fence-agents-eps |
| ||
| fence-agents-gce |
| ||
| fence-agents-heuristics-ping |
| ||
| fence-agents-hpblade |
| ||
| fence-agents-ibm-powervs |
| ||
| fence-agents-ibm-vpc |
| ||
| fence-agents-ibmblade |
| ||
| fence-agents-ifmib |
| ||
| fence-agents-ilo-moonshot |
| ||
| fence-agents-ilo-mp |
| ||
| fence-agents-ilo-ssh |
| ||
| fence-agents-ilo2 |
| ||
| fence-agents-intelmodular |
| ||
| fence-agents-ipdu |
| ||
| fence-agents-ipmilan |
| ||
| fence-agents-kdump |
| ||
| fence-agents-kubevirt |
| ||
| fence-agents-lpar |
| ||
| fence-agents-mpath |
| ||
| fence-agents-nutanix-ahv |
| ||
| fence-agents-openstack |
| ||
| fence-agents-redfish |
| ||
| fence-agents-rhevm |
| ||
| fence-agents-rsa |
| ||
| fence-agents-rsb |
| ||
| fence-agents-sbd |
| ||
| fence-agents-scsi |
| ||
| fence-agents-virsh |
| ||
| fence-agents-vmware-rest |
| ||
| fence-agents-vmware-soap |
| ||
| fence-agents-wti |
| ||
| fence-agents-zvm |
| ||
| fence-virt |
| ||
| fence-virtd |
| ||
| fence-virtd-cpg |
| ||
| fence-virtd-libvirt |
| ||
| fence-virtd-multicast |
| ||
| fence-virtd-serial |
| ||
| fence-virtd-tcp |
| ||
| ha-cloud-support |
|
Amazon Linux Releases
Common Weakness Enumeration
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
- CWE-347 - Improper Verification of Cryptographic SignatureThe software does not verify, or incorrectly verifies, the cryptographic signature for data.
Vulnerability Media Exposure
References