Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.14% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components.… | |
| Analizada | Alta (7.5) | 0.35% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result,… | |
| Analizada | Alta (7.4) | 0.18% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs when an application allows HMAC and asymmetric algorithms and passes a… | |
| Analizada | Alta (7.4) | 0.18% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a UTF-8 BOM and used… | |
| Analizada | Alta (7.4) | 0.18% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a DER public key… | |
| Analizada | Media (4.9) | 0.19% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, is_pem_format performs… | |
| Analizada | Media (5.4) | 0.20% | — | Pyjwt Project Pyjwt | 28/9/2026 | 6/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a… | |
| Modificada | Alta (7.4) | 0.43% | — | Pyjwt Project Pyjwt | 28/5/2026 | 10/9/2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC… | |
| Analizada | Media (5.3) | 0.41% | — | Pyjwt Project Pyjwt | 28/5/2026 | 17/6/2026 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT… | |
| Analizada | Baja (3.7) | 0.32% | — | Pyjwt Project Pyjwt | 28/5/2026 | 17/6/2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The… | |
| Analizada | Media (5.4) | 0.17% | — | Pyjwt Project Pyjwt | 28/5/2026 | 16/9/2026 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is… | |
| Modificada | Media (4.2) | 0.22% | — | Pyjwt Project Pyjwt | 28/5/2026 | 17/6/2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to… | |
| Modificada | Alta (7.5) | 0.28% | — | Pyjwt Project Pyjwt | 13/3/2026 | 10/9/2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates… | |
| Analizada | Alta (7) | 0.17% | — | Pyjwt Project Pyjwt | 31/7/2025 | 17/6/2026 | pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement). | |
| Modificada | Alta (7) | 0.13% | — | JWT Project JWT | 31/7/2025 | 17/6/2026 | jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an… | |
| Analizada | Alta (7.5) | 0.83% | — | Pyjwt Project Pyjwt | 29/11/2024 | 17/6/2026 | pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a… | |
| Analizada | Alta (8.4) | 0.23% | — | Json-jwt Project Json-jwt | 29/2/2024 | 17/6/2026 | The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. | |
| Modificada | Crítica (9.1) | 5.3% | — | Python-jwt Project Python-jwt | 23/9/2022 | 17/6/2026 | python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key.… | |
| Modificada | Alta (7.5) | 1.4% | — | Pyjwt Project PyjwtFedoraproject Fedora | 24/5/2022 | 17/6/2026 | PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify… | |
| Modificada | Alta (7.5) | 1.3% | — | Json-jwt Project Json-jwtDebian Linux | 12/11/2019 | 17/6/2026 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. | |
| Modificada | Crítica (9.8) | 1.1% | — | Perl-crypt-jwt Project Perl-crypt-jwt | 25/7/2019 | 17/6/2026 | perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(crafting user-controlled input to bypass authentication). The fixed version is: 0.023. | |
| Modificada | Media (5.3) | 0.78% | — | Json-jwt Project Json-jwt | 26/6/2018 | 17/6/2026 | Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability… | |
| Modificada | Crítica (9.8) | 2.0% | — | Authentikat-jwt Project Authentikat-jwt | 18/3/2018 | 17/6/2026 | A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating… | |
| Modificada | Alta (7.5) | 1.8% | — | Pyjwt Project PyjwtDebian Linux | 24/8/2017 | 17/6/2026 | In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA PUBLIC KEY-----` which is not accounted for. This enables… |