CVE-2025-45768
published 2025-07-31CVE-2025-45768: pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses…
PriorityP433high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
0.16%
5.7th percentile
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pyjwt | — | — |
| msrc | azl3_python-jwt_2.8.0-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python-jwt_2.3.0-1_on_cbl_mariner_2.0 | — | — |
| pyjwt_project | pyjwt | — | — |
| pyjwt_project | pyjwt | >= 0 < 2.13.0 | 2.13.0 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
ghsa8.8HIGH
osv7.0HIGH
vendor_debian7.0LOW
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may
vendor_msrc·2025-07-08·CVSS 7.0
CVE-2025-45768 [HIGH] CWE-311 pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for m
Debian
CVE-2025-45768: pyjwt - pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed ...
vendor_debian·2025·CVSS 7.0
CVE-2025-45768 [HIGH] CVE-2025-45768: pyjwt - pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed ...
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
ghsa·2026-06-15·CVSS 8.8
CVE-2026-48522 [HIGH] CWE-441 PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
> [!NOTE]
> The library does not directly return non-HTTP(S) URI contents to the attacker; the chained "plant a JWKS to forge tokens" scenario described in the original report requires additional application-layer flaws (attacker write access to a filesystem path, untrusted jku derivation) that this fix does not address. Severity is scored for the scheme-acceptance bug in isolation.
## Summary
PyJWKClient passes its `uri` argument directly to `urllib.request.urlopen()` which uses Python stdlib's default `OpenerDirector` registering `HTTPHandler`, `HTTPSHandler`, `FTPHandler`, **`FileHandler`**, and `DataHandler`. There is currently no documented option to restrict w
OSV
CVE-2025-45768: pyjwt v2
osv·2025-07-31·CVSS 7.0
CVE-2025-45768 [HIGH] CVE-2025-45768: pyjwt v2
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
GHSA
GHSA-xpf8-484v-j9w6: pyjwt v2
ghsa_unreviewed·2025-07-31
CVE-2025-45768 [HIGH] CWE-311 GHSA-xpf8-484v-j9w6: pyjwt v2
pyjwt v2.10.1 was discovered to contain weak encryption.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-45768 python-jwt: pyjwt Weak Encryption Vulnerability [fedora-42]
bugzilla·2025-08-01·CVSS 7.0
CVE-2025-45768 [HIGH] CVE-2025-45768 python-jwt: pyjwt Weak Encryption Vulnerability [fedora-42]
CVE-2025-45768 python-jwt: pyjwt Weak Encryption Vulnerability [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-45768 pyjwt: pyjwt Weak Encryption Vulnerability
bugzilla·2025-07-31·CVSS 7.0
CVE-2025-45768 [HIGH] CVE-2025-45768 pyjwt: pyjwt Weak Encryption Vulnerability
CVE-2025-45768 pyjwt: pyjwt Weak Encryption Vulnerability
pyjwt v2.10.1 was discovered to contain weak encryption.
Discussion:
Is there a patch available? The versions where it's fixed is only available on RHEL10.
Example from RHEL9.6:
# python3 -m pip download --no-binary :all: --no-deps PyJWT
Collecting PyJWT
Downloading pyjwt-2.10.1.tar.gz (87 kB)
|████████████████████████████████| 87 kB 6.7 MB/s
Installing build dependencies ... done
Getting requirements to build wheel ... done
Preparing metadata (pyproject.toml) ... done
Saved ./pyjwt-2.10.1.tar.gz
Successfully downloaded PyJWT
---
Correction. There is no fix available for RHEL10 either.
---
Disputed at MITRE, https://nvd.nist.gov/vuln/detail/CVE-2025-45768
Dear all: We were noticing our code was affected by this CVE, as we u
2025-07-31
Published