<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:43:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:12176 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:12176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
  * pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
  * pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
  * pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
  * pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:12176</guid>
    </item>
    <item>
      <title>bdu:2026-04360</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04360</link>
      <description>bdu:2026-04360</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04360</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-32597</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-32597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-32597</guid>
    </item>
    <item>
      <title>BREW-azure-cli-CVE-2026-32597 — PyJWT accepts unknown `crit` header extensions</title>
      <link>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-32597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; The &amp;#34;crit&amp;#34; (Critical) Header Parameter indicates that extensions to this
&amp;gt; specification and/or [JWA] are being used that **MUST** be understood and
&amp;gt; processed. [...] If any of the listed extension Header Parameters are
&amp;gt; **not understood and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json&lt;/p&gt;
&lt;p&gt;# Construct token with unknown critical extension
header = {&amp;#34;alg&amp;#34;: &amp;#34;HS256&amp;#34;, &amp;#34;crit&amp;#34;: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34;}
payload = {&amp;#34;sub&amp;#34;: &amp;#34;attacker&amp;#34;, &amp;#34;role&amp;#34;: &amp;#34;admin&amp;#34;}&lt;/p&gt;
&lt;p&gt;def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b&amp;#34;=&amp;#34;).decode()&lt;/p&gt;
&lt;p&gt;h = b64url(json.dumps(header, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
p = b64url(json.dumps(payload, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
sig = b64url(hmac.new(b&amp;#34;secret&amp;#34;, f&amp;#34;{h}.{p}&amp;#34;.encode(), hashlib.sha256).digest())
token = f&amp;#34;{h}.{p}.{sig}&amp;#34;&lt;/p&gt;
&lt;p&gt;# Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, &amp;#34;secret&amp;#34;, algorithms=[&amp;#34;HS256&amp;#34;])
    print(f&amp;#34;AC…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; The &amp;#34;crit&amp;#34; (Critical) Header Parameter indicates that extensions to this
&amp;gt; specification and/or [JWA] are being used that **MUST** be understood and
&amp;gt; processed. [...] If any of the listed extension Header Parameters are
&amp;gt; **not understood and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json&lt;/p&gt;
&lt;p&gt;# Construct token with unknown critical extension
header = {&amp;#34;alg&amp;#34;: &amp;#34;HS256&amp;#34;, &amp;#34;crit&amp;#34;: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34;}
payload = {&amp;#34;sub&amp;#34;: &amp;#34;attacker&amp;#34;, &amp;#34;role&amp;#34;: &amp;#34;admin&amp;#34;}&lt;/p&gt;
&lt;p&gt;def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b&amp;#34;=&amp;#34;).decode()&lt;/p&gt;
&lt;p&gt;h = b64url(json.dumps(header, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
p = b64url(json.dumps(payload, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
sig = b64url(hmac.new(b&amp;#34;secret&amp;#34;, f&amp;#34;{h}.{p}&amp;#34;.encode(), hashlib.sha256).digest())
token = f&amp;#34;{h}.{p}.{sig}&amp;#34;&lt;/p&gt;
&lt;p&gt;# Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, &amp;#34;secret&amp;#34;, algorithms=[&amp;#34;HS256&amp;#34;])
    print(f&amp;#34;AC…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-32597</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</link>
      <description>certfr-2026-avi-0316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AJ13963 — Security fix for CVE-2026-32597 applied in: airflow-2 2.11.2-r1, airflow-3 3.1.8-r0, airflow-3 3.2.0-r0, jupyterhub-k8s…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj13963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2, CleanStart: airflow-3, CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;CVE-2026-32597 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2, CleanStart: airflow-3, CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;CVE-2026-32597 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aj13963</guid>
    </item>
    <item>
      <title>EUVD-2026-366111</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366111</link>
      <description>EUVD-2026-366111</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366111</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32597</link>
      <description>&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32597</guid>
    </item>
    <item>
      <title>GHSA-752w-5fwx-jx9f — PyJWT accepts unknown `crit` header extensions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-752w-5fwx-jx9f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyJWT&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; The &amp;#34;crit&amp;#34; (Critical) Header Parameter indicates that extensions to this
&amp;gt; specification and/or [JWA] are being used that **MUST** be understood and
&amp;gt; processed. [...] If any of the listed extension Header Parameters are
&amp;gt; **not understood and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json&lt;/p&gt;
&lt;p&gt;# Construct token with unknown critical extension
header = {&amp;#34;alg&amp;#34;: &amp;#34;HS256&amp;#34;, &amp;#34;crit&amp;#34;: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34;}
payload = {&amp;#34;sub&amp;#34;: &amp;#34;attacker&amp;#34;, &amp;#34;role&amp;#34;: &amp;#34;admin&amp;#34;}&lt;/p&gt;
&lt;p&gt;def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b&amp;#34;=&amp;#34;).decode()&lt;/p&gt;
&lt;p&gt;h = b64url(json.dumps(header, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
p = b64url(json.dumps(payload, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
sig = b64url(hmac.new(b&amp;#34;secret&amp;#34;, f&amp;#34;{h}.{p}&amp;#34;.encode(), hashlib.sha256).digest())
token = f&amp;#34;{h}.{p}.{sig}&amp;#34;&lt;/p&gt;
&lt;p&gt;# Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, &amp;#34;secret&amp;#34;, algorithms=[&amp;#34;HS256&amp;#34;])
    print(f&amp;#34;AC…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyJWT&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PyJWT does not validate the `crit` (Critical) Header Parameter defined in
RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing
extensions that PyJWT does not understand, the library accepts the token
instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;This is the same class of vulnerability as CVE-2025-59420 (Authlib),
which received CVSS 7.5 (HIGH).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; The &amp;#34;crit&amp;#34; (Critical) Header Parameter indicates that extensions to this
&amp;gt; specification and/or [JWA] are being used that **MUST** be understood and
&amp;gt; processed. [...] If any of the listed extension Header Parameters are
&amp;gt; **not understood and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
import jwt  # PyJWT 2.8.0
import hmac, hashlib, base64, json&lt;/p&gt;
&lt;p&gt;# Construct token with unknown critical extension
header = {&amp;#34;alg&amp;#34;: &amp;#34;HS256&amp;#34;, &amp;#34;crit&amp;#34;: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34;}
payload = {&amp;#34;sub&amp;#34;: &amp;#34;attacker&amp;#34;, &amp;#34;role&amp;#34;: &amp;#34;admin&amp;#34;}&lt;/p&gt;
&lt;p&gt;def b64url(data):
    return base64.urlsafe_b64encode(data).rstrip(b&amp;#34;=&amp;#34;).decode()&lt;/p&gt;
&lt;p&gt;h = b64url(json.dumps(header, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
p = b64url(json.dumps(payload, separators=(&amp;#34;,&amp;#34;, &amp;#34;:&amp;#34;)).encode())
sig = b64url(hmac.new(b&amp;#34;secret&amp;#34;, f&amp;#34;{h}.{p}&amp;#34;.encode(), hashlib.sha256).digest())
token = f&amp;#34;{h}.{p}.{sig}&amp;#34;&lt;/p&gt;
&lt;p&gt;# Should REJECT — x-custom-policy is not understood by PyJWT
try:
    result = jwt.decode(token, &amp;#34;secret&amp;#34;, algorithms=[&amp;#34;HS256&amp;#34;])
    print(f&amp;#34;AC…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-752w-5fwx-jx9f</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-32597 — PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-32597</link>
      <description>msrc_CVE-2026-32597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-32597</guid>
    </item>
    <item>
      <title>OESA-2026-3117 — python-jwt security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-jwt, openEuler:24.03-LTS-SP1: python-jwt, openEuler:24.03-LTS-SP3: python-jwt, openEuler:24.03-LTS-SP4: python-jwt, openEuler:20.03-LTS-SP4: python-jwt&lt;/p&gt;
&lt;p&gt;rm -f tests/test_jwks_client.py  -m pytest %endif&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.(CVE-2026-32597)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-jwt, openEuler:24.03-LTS-SP1: python-jwt, openEuler:24.03-LTS-SP3: python-jwt, openEuler:24.03-LTS-SP4: python-jwt, openEuler:20.03-LTS-SP4: python-jwt&lt;/p&gt;
&lt;p&gt;rm -f tests/test_jwks_client.py  -m pytest %endif&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.(CVE-2026-32597)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3117</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10397-1 — python311-PyJWT-2.12.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10397-1</link>
      <description>&lt;p&gt;python311-PyJWT-2.12.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-PyJWT-2.12.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10397-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-120</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-120</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-120</guid>
    </item>
    <item>
      <title>RHSA-2026:10140 — Red Hat Security Advisory: Red Hat Enterprise Linux AI 3.3.1</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10140</link>
      <description>&lt;p&gt;python: Python: Command-line option injection in webbrowser.open() via crafted URLs python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules net/url: Incorrect parsing of IPv6 host literals in net/url vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python: Command-line option injection in webbrowser.open() via crafted URLs python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules net/url: Incorrect parsing of IPv6 host literals in net/url vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10140</guid>
    </item>
    <item>
      <title>RLSA-2026:19138 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19138</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19138</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1199-1 — Security update for python-PyJWT</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1199-1</link>
      <description>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1199-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-32597</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32597</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</guid>
    </item>
  </channel>
</rss>
