cbcvebase.
CVE-2025-45768
published 2025-07-31

CVE-2025-45768: pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses…

PriorityP433high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
0.16%
5.7th percentile
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

Affected

5 ranges
VendorProductVersion rangeFixed in
debianpyjwt
msrcazl3_python-jwt_2.8.0-1_on_azure_linux_3.0
msrccbl2_python-jwt_2.3.0-1_on_cbl_mariner_2.0
pyjwt_projectpyjwt
pyjwt_projectpyjwt>= 0 < 2.13.02.13.0

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
ghsa8.8HIGH
osv7.0HIGH
vendor_debian7.0LOW
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.