from 0, < 1.7.1-2+deb11u1
from 0, < 1.4.2-1.1
from 0, < 0.2.1-1+deb8u2
HIGH7.4PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
from 0
HIGH7.4Key confusion through non-blocklisted public key formats
from 0, < 2.4.0-1
HIGH7.0pyjwt v2.10.1 was discovered to contain weak encryption.
from 0
MEDIUM5.4PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
from 0
MEDIUM5.3PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
from 0
MEDIUM4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
from 0
LOW3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
from 0