CVE-2025-45768

NameCVE-2025-45768
Descriptionpyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1110318

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pyjwt (PTS)bullseye1.7.1-2vulnerable
bookworm2.6.0-1vulnerable
trixie2.10.1-2vulnerable
forky, sid2.10.1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pyjwtsource(unstable)(unfixed)unimportant1110318

Notes

disputed upstream, negligible security impact, cf.
https://github.com/jpadilla/pyjwt/issues/1080#issuecomment-3164212492
https://github.com/advisories/GHSA-xpf8-484v-j9w6
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-72ff-rqxp-4hrh

Search for package or bug name: Reporting problems