PT-2026-65869 · Pypi · Joserfc

CVE-2026-62995

·

Published

2026-07-29

·

Updated

2026-08-01

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions joserfc versions prior to 1.7.2
Description The library accepts JSON Web Tokens (JWTs) containing trailing padding (==), which does not conform to JSON Object Signing and Encryption (JOSE) specifications. This results in token malleability, where a token can be modified without invalidating its signature. This behavior may allow attackers to bypass anti-replay protections or token revocation mechanisms that rely on deny lists of tokens or token hashes. While ECDSA JSON Web Signatures (JWS) are inherently malleable due to the nature of ECDSA signatures, this issue affects other signature or Message Authentication Code (MAC) schemes that assume tokens are non-malleable.
Recommendations Update to version 1.7.2.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62995
GHSA-5JHW-7JV7-QCQQ
OPENSUSE-SU-2026:11423-1
OPENSUSE-SU-2026:21515-1
RHSA-2026:48758

Affected Products

Joserfc