CVE-2022-29217
published 2022-05-24CVE-2022-29217: PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.20%
64.7th percentile
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always be explicit with the algorithms that are accepted and expected when decoding.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| authlib | authlib | < 1.3.1 | 1.3.1 |
| authlib | authlib | >= 0 < 1.3.1 | 1.3.1 |
| debian | pyjwt | < pyjwt 2.4.0-1 (bookworm) | pyjwt 2.4.0-1 (bookworm) |
| debian | python-authlib | < python-authlib 0.15.4-1+deb11u1 (bullseye) | python-authlib 0.15.4-1+deb11u1 (bullseye) |
| debian | python-jose | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python-jwt_2.4.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python-jwt_2.4.0-1_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
| pyjwt_project | pyjwt | >= 0 < 2.4.0-1 | 2.4.0-1 |
| pyjwt_project | pyjwt | >= 0 < 2.4.0-1 | 2.4.0-1 |
| pyjwt_project | pyjwt | >= 0 < 2.4.0-1 | 2.4.0-1 |
| pyjwt_project | pyjwt | >= 0 < 2.13.0 | 2.13.0 |
| pyjwt_project | pyjwt | >= 1.5.0 < 2.4.0 | 2.4.0 |
| pyjwt_project | pyjwt | >= 1.5.0 < 2.4.0 | 2.4.0 |
| python-jose_project | python-jose | <= 3.3.0 | — |
| python-jose_project | python-jose | >= 0 < 3.4.0 | 3.4.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa8.8HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
vendor_redhat·2024-04-26·CVSS 7.4
CVE-2024-33663 [HIGH] python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Package: python-jose (Red Hat Ansible Automation Platform 2) - Not affected
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Debian
CVE-2024-33663: python-jose - python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and ot...
vendor_debian·2024·CVSS 7.4
CVE-2024-33663 [HIGH] CVE-2024-33663: python-jose - python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and ot...
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Scope: local
bookworm: open
Debian
CVE-2024-37568: python-authlib - lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys...
vendor_debian·2024·CVSS 7.4
CVE-2024-37568 [HIGH] CVE-2024-37568: python-authlib - lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys...
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Scope: local
bookworm: open
bullseye: resolved (fixed in 0.15.4-1+deb11u1)
forky: resolved (fixed in 1.3.1-1)
sid: resolved (fixed in 1.3.1-1)
trixie: resolved (fixed in 1.3.1-1)
Ubuntu
PyJWT vulnerability
vendor_ubuntu·2022-07-20
CVE-2022-29217 PyJWT vulnerability
Title: PyJWT vulnerability
Summary: PyJWT could allow signature forgery.
Aapo Oksman discovered that PyJWT incorrectly handled signatures
constructed from SSH public keys. A remote attacker could use this to forge
a JWT signature.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-jwt: Key confusion through non-blocklisted public key formats
vendor_redhat·2022-05-12·CVSS 7.4
CVE-2022-29217 [HIGH] CWE-327 python-jwt: Key confusion through non-blocklisted public key formats
python-jwt: Key confusion through non-blocklisted public key formats
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always be explicit with the algorithms that are accepted and expected when decoding.
A vulnerability was found in python-jwt. This issu
Microsoft
Key confusion through non-blocklisted public key formats in PyJWT
vendor_msrc·2022-05-10·CVSS 7.5
CVE-2022-29217 [HIGH] CWE-327 Key confusion through non-blocklisted public key formats in PyJWT
Key confusion through non-blocklisted public key formats in PyJWT
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Referenc
Debian
CVE-2022-29217: pyjwt - PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different ...
vendor_debian·2022·CVSS 7.4
CVE-2022-29217 [HIGH] CVE-2022-29217: pyjwt - PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different ...
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always be explicit with the algorithms that are accepted and expected when decoding.
Scope: local
bookworm: resolved (fixed in 2.4.0-1)
bullseye: resolved
forky: resolved (fixed in 2.4.0-1)
sid: resolved (f
GHSA
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
ghsa·2026-06-15·CVSS 8.8
CVE-2026-48522 [HIGH] CWE-441 PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
> [!NOTE]
> The library does not directly return non-HTTP(S) URI contents to the attacker; the chained "plant a JWKS to forge tokens" scenario described in the original report requires additional application-layer flaws (attacker write access to a filesystem path, untrusted jku derivation) that this fix does not address. Severity is scored for the scheme-acceptance bug in isolation.
## Summary
PyJWKClient passes its `uri` argument directly to `urllib.request.urlopen()` which uses Python stdlib's default `OpenerDirector` registering `HTTPHandler`, `HTTPSHandler`, `FTPHandler`, **`FileHandler`**, and `DataHandler`. There is currently no documented option to restrict w
OSV
CVE-2024-37568: lepture Authlib before 1
osv·2024-06-09·CVSS 7.5
CVE-2024-37568 [HIGH] CVE-2024-37568: lepture Authlib before 1
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
OSV
Authlib has algorithm confusion with asymmetric public keys
osv·2024-06-09·CVSS 7.5
CVE-2024-37568 [HIGH] Authlib has algorithm confusion with asymmetric public keys
Authlib has algorithm confusion with asymmetric public keys
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
GHSA
Authlib has algorithm confusion with asymmetric public keys
ghsa·2024-06-09·CVSS 7.5
CVE-2024-37568 [HIGH] CWE-284 Authlib has algorithm confusion with asymmetric public keys
Authlib has algorithm confusion with asymmetric public keys
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
OSV
CVE-2024-33663: python-jose through 3
osv·2024-04-26·CVSS 7.5
CVE-2024-33663 [HIGH] CVE-2024-33663: python-jose through 3
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
OSV
python-jose algorithm confusion with OpenSSH ECDSA keys
osv·2024-04-26·CVSS 7.5
CVE-2024-33663 [HIGH] python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
GHSA
python-jose algorithm confusion with OpenSSH ECDSA keys
ghsa·2024-04-26·CVSS 7.5
CVE-2024-33663 [HIGH] CWE-327 python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
OSV
CVE-2022-29217: PyJWT is a Python implementation of RFC 7519
osv·2022-05-24·CVSS 7.5
CVE-2022-29217 [HIGH] CVE-2022-29217: PyJWT is a Python implementation of RFC 7519
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always be explicit with the algorithms that are accepted and expected when decoding.
OSV
Key confusion through non-blocklisted public key formats
osv·2022-05-24
CVE-2022-29217 [HIGH] Key confusion through non-blocklisted public key formats
Key confusion through non-blocklisted public key formats
### Impact
_What kind of vulnerability is it? Who is impacted?_
Disclosed by Aapo Oksman (Senior Security Specialist, Nixu Corporation).
> PyJWT supports multiple different JWT signing algorithms. With JWT, an
> attacker submitting the JWT token can choose the used signing algorithm.
>
> The PyJWT library requires that the application chooses what algorithms
> are supported. The application can specify
> "jwt.algorithms.get_default_algorithms()" to get support for all
> algorithms. They can also specify a single one of them (which is the
> usual use case if calling jwt.decode directly. However, if calling
> jwt.decode in a helper function, all algorithms might be enabled.)
>
> For example, if the user chooses "none" algorithm and
GHSA
Key confusion through non-blocklisted public key formats
ghsa·2022-05-24
CVE-2022-29217 [HIGH] CWE-327 Key confusion through non-blocklisted public key formats
Key confusion through non-blocklisted public key formats
### Impact
_What kind of vulnerability is it? Who is impacted?_
Disclosed by Aapo Oksman (Senior Security Specialist, Nixu Corporation).
> PyJWT supports multiple different JWT signing algorithms. With JWT, an
> attacker submitting the JWT token can choose the used signing algorithm.
>
> The PyJWT library requires that the application chooses what algorithms
> are supported. The application can specify
> "jwt.algorithms.get_default_algorithms()" to get support for all
> algorithms. They can also specify a single one of them (which is the
> usual use case if calling jwt.decode directly. However, if calling
> jwt.decode in a helper function, all algorithms might be enabled.)
>
> For example, if the user chooses "none" algorithm and
No detection rules found.
No public exploits indexed.
arXiv
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
arxiv_fulltext·2025-09-03
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
Weizhe Wang
Co-first author.
Tianjin University
China
Wei Ma
[1]
Singapore Management University
Singapore
Qiang Hu
Tianjin University
China
Yao Zhang
Corresponding author. [email protected], [email protected]
Tianjin University
China
Jianfei Sun
Singapore Management University
Singapore
Bin Wu
Tianjin University
China
Yang Liu
Nanyang Technological University
Singapore
Guangquan Xu
[2]
Tianjin University
China
Lingxiao Jiang
Singapore Management University
Singapore
Wang and Ma et al.
software vulnerability repair, LLM, exploit-based evaluation, benchmark
## Abstract
The adoption of Large Language Models (LLMs) for automated software vulnerability patching has sh
Bugzilla
CVE-2024-33663 python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
bugzilla·2024-04-26·CVSS 7.5
CVE-2024-33663 [HIGH] CVE-2024-33663 python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
CVE-2024-33663 python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
https://github.com/mpdavis/python-jose/issues/346
Discussion:
Created python-jose tracking bugs for this issue:
Affects: fedora-all [bug 2277299]
---
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.4 for RHEL 9
Red Hat Ansible Automation Platform 2.4 for RHEL 8
Via RHSA-2024:6428 https://access.redhat.com/errata/RHSA-2024:6428
Bugzilla
CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats
bugzilla·2022-05-19·CVSS 7.5
CVE-2022-29217 [HIGH] CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats
CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats
PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm.
The PyJWT library requires that the application chooses what algorithms are supported. The application can specify "jwt.algorithms.get_default_algorithms()" to get support for all algorithms. They can also specify a single one of them (which is the usual use case if calling jwt.decode directly. However, if calling jwt.decode in a helper function, all algorithms might be enabled.)
For example, if the user chooses "none" algorithm and the JWT checker supports that, there will be no signature checking. This is a common security issue with some JWT implementations.
https://github.com/jpadilla/pyjwt/commit/9c528670c455b8d948aff95ed50e22940d1ad3fchttps://github.com/jpadilla/pyjwt/releases/tag/2.4.0https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PK7IQCBVNLYJEFTPHBBPFP72H4WUFNX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HIYEYZRQEP6QTHT3EHH3RGFYJIHIMAO/https://github.com/jpadilla/pyjwt/commit/9c528670c455b8d948aff95ed50e22940d1ad3fchttps://github.com/jpadilla/pyjwt/releases/tag/2.4.0https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PK7IQCBVNLYJEFTPHBBPFP72H4WUFNX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6HIYEYZRQEP6QTHT3EHH3RGFYJIHIMAO/https://www.vicarius.io/vsociety/posts/risky-algorithms-algorithm-confusion-in-pyjwt-cve-2022-29217
2022-05-24
Published