<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:43:59.504191+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:12176</id>
    <title>ALSA-2026:12176 — Important: fence-agents security update</title>
    <updated>2026-10-02T10:43:59.857135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
  * pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
  * pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:12176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04360</id>
    <title>bdu:2026-04360</title>
    <updated>2026-10-02T10:43:59.857294+00:00</updated>
    <content>bdu:2026-04360</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-32597</id>
    <title>BELL-CVE-2026-32597</title>
    <updated>2026-10-02T10:43:59.857314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-32597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-32597</id>
    <title>BREW-azure-cli-CVE-2026-32597 — PyJWT accepts unknown `crit` header extensions</title>
    <updated>2026-10-02T10:43:59.857334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: azure-cli</p>
<p>## Summary</p>
<p>PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.</p>
<p>This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).</p>
<p>---</p>
<p>## RFC Requirement</p>
<p>RFC 7515 §4.1.11:</p>
<p>&gt; The "crit" (Critical) Header Parameter indicates that extensions to this
&gt; specification and/or [JWA] are being used that **MUST** be understood and
&gt; processed. [...] If any of the listed extension Header Parameters are
&gt; **not understood and supported** by the recipient, then the **JWS is invalid**.</p>
<p>---</p>
<p>## Proof of Concept</p>
<p>```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json</p>
<p># Construct token with unknown critical extension
header = {"alg": "HS256", "crit": ["x-custom-policy"], "x-custom-policy": "require-mfa"}
payload = {"sub": "attacker", "role": "admin"}</p>
<p>def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b"=").decode()</p>
<p>h = b64url(json.dumps(header, separators=(",", ":")).encode())
p = b64url(json.dumps(payload, separators=(",", ":")).encode())
sig = b64url(hmac.new(b"secret", f"{h}.{p}".encode(), hashlib.sha256).digest())
token = f"{h}.{p}.{sig}"</p>
<p># Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, "secret", algorithms=["HS256"])
    print(f"AC…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-32597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</id>
    <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T10:43:59.857395+00:00</updated>
    <content>certfr-2026-avi-0316</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj13963</id>
    <title>CLEANSTART-2026-AJ13963 — Security fix for CVE-2026-32597 applied in: airflow-2 2.11.2-r1, airflow-3 3.1.8-r0, airflow-3 3.2.0-r0, jupyterhub-k8s…</title>
    <updated>2026-10-02T10:43:59.857412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: airflow-2, CleanStart: airflow-3, CleanStart: jupyterhub-k8s-hub</p>
<p>CVE-2026-32597 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aj13963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366111</id>
    <title>EUVD-2026-366111</title>
    <updated>2026-10-02T10:43:59.857438+00:00</updated>
    <content>EUVD-2026-366111</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32597</id>
    <title>fkie_cve-2026-32597</title>
    <updated>2026-10-02T10:43:59.857450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-752w-5fwx-jx9f</id>
    <title>GHSA-752w-5fwx-jx9f — PyJWT accepts unknown `crit` header extensions</title>
    <updated>2026-10-02T10:43:59.857473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PyJWT</p>
<p>## Summary</p>
<p>PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.</p>
<p>This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).</p>
<p>---</p>
<p>## RFC Requirement</p>
<p>RFC 7515 §4.1.11:</p>
<p>&gt; The "crit" (Critical) Header Parameter indicates that extensions to this
&gt; specification and/or [JWA] are being used that **MUST** be understood and
&gt; processed. [...] If any of the listed extension Header Parameters are
&gt; **not understood and supported** by the recipient, then the **JWS is invalid**.</p>
<p>---</p>
<p>## Proof of Concept</p>
<p>```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json</p>
<p># Construct token with unknown critical extension
header = {"alg": "HS256", "crit": ["x-custom-policy"], "x-custom-policy": "require-mfa"}
payload = {"sub": "attacker", "role": "admin"}</p>
<p>def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b"=").decode()</p>
<p>h = b64url(json.dumps(header, separators=(",", ":")).encode())
p = b64url(json.dumps(payload, separators=(",", ":")).encode())
sig = b64url(hmac.new(b"secret", f"{h}.{p}".encode(), hashlib.sha256).digest())
token = f"{h}.{p}.{sig}"</p>
<p># Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, "secret", algorithms=["HS256"])
    print(f"AC…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-752w-5fwx-jx9f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-32597</id>
    <title>msrc_CVE-2026-32597 — PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)</title>
    <updated>2026-10-02T10:43:59.857528+00:00</updated>
    <content>msrc_CVE-2026-32597</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-32597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3117</id>
    <title>OESA-2026-3117 — python-jwt security update</title>
    <updated>2026-10-02T10:43:59.857546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-jwt, openEuler:24.03-LTS-SP1: python-jwt, openEuler:24.03-LTS-SP3: python-jwt, openEuler:24.03-LTS-SP4: python-jwt, openEuler:20.03-LTS-SP4: python-jwt</p>
<p>rm -f tests/test_jwks_client.py  -m pytest %endif

Security Fix(es):</p>
<p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.(CVE-2026-32597)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10397-1</id>
    <title>openSUSE-SU-2026:10397-1 — python311-PyJWT-2.12.1-1.1 on GA media</title>
    <updated>2026-10-02T10:43:59.857575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-PyJWT-2.12.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10397-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-120</id>
    <title>PYSEC-2026-120</title>
    <updated>2026-10-02T10:43:59.857592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyjwt</p>
<p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10140</id>
    <title>RHSA-2026:10140 — Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.1</title>
    <updated>2026-10-02T10:43:59.857611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: Python: Command-line option injection in webbrowser.open() via crafted URLs python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules net/url: Incorrect parsing of IPv6 host literals in net/url vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19138</id>
    <title>RLSA-2026:19138 — Important: fence-agents security update</title>
    <updated>2026-10-02T10:43:59.857637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: fence-agents</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)</p>
<p>* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1199-1</id>
    <title>SUSE-SU-2026:1199-1 — Security update for python-PyJWT</title>
    <updated>2026-10-02T10:43:59.857661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-PyJWT</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1199-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32597</id>
    <title>UBUNTU-CVE-2026-32597</title>
    <updated>2026-10-02T10:43:59.857676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt</p>
<p>PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</id>
    <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:43:59.857703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933"/>
  </entry>
</feed>
