云虫漏洞库

CVE-2026-48526 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0. - 漏洞详情

漏洞编号:CVE-2026-48526

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-48526

CNNVD 编号:-

厂商/产品:pyjwt_project / pyjwt

影响范围:cpe:2.3:a:pyjwt_project:pyjwt:*:*:*:*:*:*:*:*

CWE:CWE-287

发布/更新时间:2026-05-28 / 2026-08-28

漏洞描述

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

相关链接

相关漏洞

« 返回首页