<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:42:51 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2024-53861 — CVE-2024-53861 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-53861</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-53861</guid>
    </item>
    <item>
      <title>BREW-bbot-CVE-2024-53861 — PyJWT Issuer field partial matches allowed</title>
      <link>https://cve.radiocsirt.org/vuln/brew-bbot-cve-2024-53861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bbot&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: bbot&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-bbot-cve-2024-53861</guid>
    </item>
    <item>
      <title>EUVD-2026-205339</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-205339</link>
      <description>EUVD-2026-205339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-205339</guid>
    </item>
    <item>
      <title>fkie_cve-2024-53861</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-53861</link>
      <description>&lt;p&gt;pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`. This is a bug introduced in version 2.10.0: checking the &amp;#34;iss&amp;#34; claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a Sequnce, but not a list, `in` is also used for string comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`. Signature checks are still present so real world impact is likely limited to denial of service scenarios. This issue has been patched in version 2.10.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`. This is a bug introduced in version 2.10.0: checking the &amp;#34;iss&amp;#34; claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a Sequnce, but not a list, `in` is also used for string comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`. Signature checks are still present so real world impact is likely limited to denial of service scenarios. This issue has been patched in version 2.10.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-53861</guid>
    </item>
    <item>
      <title>GHSA-75c5-xw7c-p5pm — PyJWT Issuer field partial matches allowed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-75c5-xw7c-p5pm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyJWT&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyJWT&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-75c5-xw7c-p5pm</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14540-1 — python310-PyJWT-2.10.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14540-1</link>
      <description>&lt;p&gt;python310-PyJWT-2.10.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-PyJWT-2.10.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14540-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1814 — PyJWT Issuer field partial matches allowed</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1814</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;### Summary
The wrong string if check is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`.&lt;/p&gt;
&lt;p&gt;### Details
This is a bug introduced in version [2.10.0](https://github.com/jpadilla/pyjwt/commit/1570e708672aa9036bc772476beae8bfa48f4131#diff-6893ad4a1c5a36b8af3028db8c8bc3b62418149843fc382faf901eaab008e380R366): checking the &amp;#34;iss&amp;#34; claim
changed from `isinstance(issuer, list)` to `isinstance(issuer,
Sequence)`.&lt;/p&gt;
&lt;p&gt;```diff
-        if isinstance(issuer, list):
+        if isinstance(issuer, Sequence):
            if payload[&amp;#34;iss&amp;#34;] not in issuer:
                raise InvalidIssuerError(&amp;#34;Invalid issuer&amp;#34;)
        else:
```&lt;/p&gt;
&lt;p&gt;Since str is a Sequnce, but not a list, `in` is also used for string
comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being
checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`.
### PoC
Check out the unit tests added here: https://github.com/jpadilla/pyjwt-ghsa-75c5-xw7c-p5pm
```python
        issuer = &amp;#34;urn:expected&amp;#34;&lt;/p&gt;
&lt;p&gt;payload = {&amp;#34;iss&amp;#34;: &amp;#34;urn:&amp;#34;}&lt;/p&gt;
&lt;p&gt;token = jwt.encode(payload, &amp;#34;secret&amp;#34;)&lt;/p&gt;
&lt;p&gt;# decode() succeeds, even though `&amp;#34;urn:&amp;#34; != &amp;#34;urn:expected&amp;#34;. No exception is raised.
        with pytest.raises(InvalidIssuerError):
            jwt.decode(token, &amp;#34;secret&amp;#34;, issuer=issuer, algorithms=[&amp;#34;HS256&amp;#34;])
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;I would say the real world impact is not that high, seeing as the signature still has to match. We should still fix it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1814</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20879-1 — Security update for python-PyJWT</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20879-1</link>
      <description>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20879-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-53861</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53861</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.10: pyjwt, Ubuntu:24.04:LTS: pyjwt&lt;/p&gt;
&lt;p&gt;pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`. This is a bug introduced in version 2.10.0: checking the &amp;#34;iss&amp;#34; claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a Sequnce, but not a list, `in` is also used for string comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`. Signature checks are still present so real world impact is likely limited to denial of service scenarios. This issue has been patched in version 2.10.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.10: pyjwt, Ubuntu:24.04:LTS: pyjwt&lt;/p&gt;
&lt;p&gt;pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `&amp;#34;acb&amp;#34;` being accepted for `&amp;#34;_abc_&amp;#34;`. This is a bug introduced in version 2.10.0: checking the &amp;#34;iss&amp;#34; claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequence)`. Since str is a Sequnce, but not a list, `in` is also used for string comparison. This results in `if &amp;#34;abc&amp;#34; not in &amp;#34;__abcd__&amp;#34;:` being checked instead of `if &amp;#34;abc&amp;#34; != &amp;#34;__abc__&amp;#34;:`. Signature checks are still present so real world impact is likely limited to denial of service scenarios. This issue has been patched in version 2.10.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53861</guid>
    </item>
  </channel>
</rss>
