CVE-2026-85394

NameCVE-2026-85394
Descriptionpython-jose through 3.5.0 fails to properly validate asymmetric keys i ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-jose (PTS)bookworm3.3.0+dfsg-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-josesource(unstable)(not affected)

Notes

- python-jose <not-affected> (Incomplete fix for CVE-2024-33663 not applied)
https://github.com/mpdavis/python-jose/issues/414
CVE exists due to an incomplete fix for CVE-2024-33663

Search for package or bug name: Reporting problems