<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:47:53.459413+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-bbot-cve-2024-53861</id>
    <title>BREW-bbot-CVE-2024-53861 — PyJWT Issuer field partial matches allowed</title>
    <updated>2026-10-04T21:47:53.480005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: bbot</p>
<p>### Summary
The wrong string if check is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`.</p>
<p>### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the "iss" claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.</p>
<p>```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload["iss"] not in issuer:
                raise InvalidIssuerError("Invalid issuer")
        else:
```</p>
<p>Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if "abc" not in "__abcd__":` being
checked instead of `if "abc" != "__abc__":`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = "urn:expected"</p>
<p>payload = {"iss": "urn:"}</p>
<p>token = jwt.encode(payload, "secret")</p>
<p># decode() succeeds, even though `"urn:" != "urn:expected". No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, "secret", issuer=issuer, algorithms=["HS256"])
```</p>
<p>### Impact</p>
<p>I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-bbot-cve-2024-53861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-53861</id>
    <title>CVE-2024-53861 — Issuer field partial matches allowed in pyjwt</title>
    <updated>2026-10-04T21:47:53.480083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> jpadilla pyjwt, pyjwt_project pyjwt</p>
<p>pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a Sequnce, but not a list, `in` is also used for string comparison. This results in `if "abc" not in "__abcd__":` being checked instead of `if "abc" != "__abc__":`. Signature checks are still present so real world impact is likely limited to denial of service scenarios. This issue has been patched in version 2.10.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-53861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-75c5-xw7c-p5pm</id>
    <title>GHSA-75c5-xw7c-p5pm — PyJWT Issuer field partial matches allowed</title>
    <updated>2026-10-04T21:47:53.480123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PyJWT</p>
<p>### Summary
The wrong string if check is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`.</p>
<p>### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the "iss" claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.</p>
<p>```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload["iss"] not in issuer:
                raise InvalidIssuerError("Invalid issuer")
        else:
```</p>
<p>Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if "abc" not in "__abcd__":` being
checked instead of `if "abc" != "__abc__":`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = "urn:expected"</p>
<p>payload = {"iss": "urn:"}</p>
<p>token = jwt.encode(payload, "secret")</p>
<p># decode() succeeds, even though `"urn:" != "urn:expected". No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, "secret", issuer=issuer, algorithms=["HS256"])
```</p>
<p>### Impact</p>
<p>I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-75c5-xw7c-p5pm"/>
  </entry>
</feed>
