PT-2026-65869 · Pypi · Joserfc
CVE-2026-62995
·
Published
2026-07-29
·
Updated
2026-08-01
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
joserfc versions prior to 1.7.2
Description
The library accepts JSON Web Tokens (JWTs) containing trailing padding (==), which does not conform to JSON Object Signing and Encryption (JOSE) specifications. This results in token malleability, where a token can be modified without invalidating its signature. This behavior may allow attackers to bypass anti-replay protections or token revocation mechanisms that rely on deny lists of tokens or token hashes. While ECDSA JSON Web Signatures (JWS) are inherently malleable due to the nature of ECDSA signatures, this issue affects other signature or Message Authentication Code (MAC) schemes that assume tokens are non-malleable.
Recommendations
Update to version 1.7.2.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joserfc