Vulnerabilities

Last updated 10 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
pyjwt PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set Medium Risk 5.9 3 hours ago 3 hours ago
pyjwt PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed High Risk 7.4 3 months ago 19 days ago
pyjwt PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys Medium Risk 5.4 3 months ago 19 days ago
pyjwt PyJWT accepts unknown `crit` header extensions High Risk 7.5 6 months ago 19 days ago
pyjwt PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS Medium Risk 5.3 3 months ago 19 days ago
pyjwt PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes Medium Risk 4.2 3 months ago 19 days ago
pyjwt PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) Low Risk 3.7 3 months ago 19 days ago
pyjwt PyJWT Issuer field partial matches allowed Low Risk 2.2 1 year ago 19 days ago
pyjwt PyJWT Issuer field partial matches allowed Low Risk 2.2 2 months ago 2 months ago
pyjwt No summary available Medium Risk 5.4 4 months ago 3 months ago
pyjwt No summary available Low Risk 3.7 4 months ago 3 months ago
pyjwt No summary available Medium Risk 5.3 4 months ago 3 months ago
pyjwt No summary available High Risk 7.4 4 months ago 3 months ago
pyjwt No summary available Medium Risk 4.2 4 months ago 3 months ago
pyjwt No summary available High Risk 7.0 1 year ago 4 months ago
pyjwt No summary available High Risk 7.5 6 months ago 4 months ago
pyjwt Malicious code in pyjwt (npm) Unknown 11 months ago 11 months ago
pyjwt PyJWT vulnerable to key confusion attacks High Risk 7.5 4 years ago 1 year ago
pyjwt Key confusion through non-blocklisted public key formats High Risk 7.4 4 years ago 1 year ago
pyjwt No summary available Unknown 4 years ago 2 years ago
pyjwt No summary available Unknown 9 years ago 2 years ago
pyjwtrequest Malicious code in pyjwtrequest (PyPI) Unknown 3 years ago 3 years ago