<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:26:06.172828+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:25902</id>
    <title>ALSA-2026:25902 — Important: fence-agents security update</title>
    <updated>2026-10-03T15:26:08.049397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: fence-agents-aliyun, AlmaLinux:10: fence-agents-all, AlmaLinux:10: fence-agents-amt-ws, AlmaLinux:10: fence-agents-apc, AlmaLinux:10: fence-agents-apc-snmp, AlmaLinux:10: fence-agents-aws, AlmaLinux:10: fence-agents-azure-arm, AlmaLinux:10: fence-agents-bladecenter, AlmaLinux:10: fence-agents-brocade, AlmaLinux:10: fence-agents-cisco-mds and 45 more</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:25902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-48526</id>
    <title>BELL-CVE-2026-48526</title>
    <updated>2026-10-03T15:26:08.049573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-48526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-48526</id>
    <title>BREW-azure-cli-CVE-2026-48526 — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
    <updated>2026-10-03T15:26:08.049601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: azure-cli</p>
<p>&gt; [!NOTE]
&gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.</p>
<p>### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.</p>
<p>### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=["HS256","RS256"])) `</p>
<p>An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.</p>
<p>If we look on current protections implemented in the library, at class HMACAlgorithm:</p>
<p>```
  def prepare_key(self, key: str | bytes) -&gt; bytes:
        key_bytes = force_bytes(key)</p>
<p>if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                "The specified key is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-48526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</id>
    <title>Withdrawn: CLEANSTART-2026-AF67526 — Security fixes for CVE-2026-42304, CVE-2026-44307, CVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-…</title>
    <updated>2026-10-03T15:26:08.049657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: jupyterhub-k8s-hub</p>
<p>Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366080</id>
    <title>EUVD-2026-366080</title>
    <updated>2026-10-03T15:26:08.049681+00:00</updated>
    <content>EUVD-2026-366080</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48526</id>
    <title>fkie_cve-2026-48526</title>
    <updated>2026-10-03T15:26:08.049694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xgmm-8j9v-c9wx</id>
    <title>GHSA-xgmm-8j9v-c9wx — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
    <updated>2026-10-03T15:26:08.049719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyjwt</p>
<p>&gt; [!NOTE]
&gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.</p>
<p>### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.</p>
<p>### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=["HS256","RS256"])) `</p>
<p>An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.</p>
<p>If we look on current protections implemented in the library, at class HMACAlgorithm:</p>
<p>```
  def prepare_key(self, key: str | bytes) -&gt; bytes:
        key_bytes = force_bytes(key)</p>
<p>if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                "The specified key is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xgmm-8j9v-c9wx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48526</id>
    <title>msrc_CVE-2026-48526 — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
    <updated>2026-10-03T15:26:08.049773+00:00</updated>
    <content>msrc_CVE-2026-48526</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-48526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11024-1</id>
    <title>openSUSE-SU-2026:11024-1 — python311-PyJWT-2.13.0-1.1 on GA media</title>
    <updated>2026-10-03T15:26:08.049792+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-PyJWT-2.13.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11024-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-179</id>
    <title>PYSEC-2026-179</title>
    <updated>2026-10-03T15:26:08.049813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyjwt</p>
<p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-179"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25928</id>
    <title>RHSA-2026:25928 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
    <updated>2026-10-03T15:26:08.049833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible-lightspeed: Ansible Lightspeed: Session hijacking and unauthorized data access due to insufficient session expiration urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:25902</id>
    <title>RLSA-2026:25902 — Important: fence-agents security update</title>
    <updated>2026-10-03T15:26:08.049858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: fence-agents</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:25902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22138-1</id>
    <title>SUSE-SU-2026:22138-1 — Security update for python-PyJWT</title>
    <updated>2026-10-03T15:26:08.049881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-PyJWT</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22138-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48526</id>
    <title>UBUNTU-CVE-2026-48526</title>
    <updated>2026-10-03T15:26:08.049899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt, Ubuntu:26.04:LTS: pyjwt</p>
<p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923</id>
    <title>WID-SEC-W-2026-1923 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:26:08.049928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923"/>
  </entry>
</feed>
