gpp_maybe Security update for python-jwcrypto
SUSE-SLES-16.0-652


This update for python-jwcrypto fixes the following issues: - CVE-2026-39373: weak mitigation for JWT bomb attack in the `deserialize` function can lead to memory exhaustion via crafted compressed JWE tokens (bsc#1261802).

  • Release Date
    Apr 29 2026
  • References
    Bugzilla: 1261802
    CVEs: CVE-2026-39373
  • Type
    security
  • Severity
    important

cloud_download Downloads

SUSE Linux Enterprise Server 16.0 s390x
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 ppc64le
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 aarch64
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 x86_64
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
  • Packages
    python313-jwcrypto
    Python module package implementing JOSE Web standards
    1.5.6-160000.3.1 lock rpm