Vulnerability GHSA-3qf3-8w2g-rqmx
Critical
CRITICAL RISK
CVSS Score: 9.1
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
1 month ago
September 03, 2026 at 09:31 PM UTC
python-jose algorithm confusion guard bypassed by DER-encoded public keys
0.1.0 - 3.5.0
0.1.0 - 3.5.0
Summary
python-jose algorithm confusion guard bypassed by DER-encoded public keys
Details
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 months ago
No summary available
0.1.0 - 3.3.0 PYSEC-2025-185
0.1.0 - 3.3.0 PYSEC-2025-185
High Risk
2 years ago
python-jose algorithm confusion with OpenSSH ECDSA keys
0.1.0 - 3.3.0 GHSA-6c5p-j8vq-pqhj
0.1.0 - 3.3.0 GHSA-6c5p-j8vq-pqhj
Medium Risk
2 years ago
python-jose denial of service via compressed JWE content
0.1.0 - 3.3.0 GHSA-cjwg-qfpm-7377
0.1.0 - 3.3.0 GHSA-cjwg-qfpm-7377
Unknown
2 years ago
No summary available
0.1.0 - 3.3.0 PYSEC-2024-232
0.1.0 - 3.3.0 PYSEC-2024-232
Unknown
2 years ago
No summary available
0.1.0 - 3.3.0 PYSEC-2024-233
0.1.0 - 3.3.0 PYSEC-2024-233
Impacted packages
Timeline
Published
1 month ago
September 03, 2026 at 09:31 PM UTC
Last Modified
7 hours ago
October 05, 2026 at 11:25 PM UTC