gpp_maybe
Security update for python-jwcrypto
openSUSE-2026-129
This update for python-jwcrypto fixes the following issues: - CVE-2022-3102: jwcrypto token substitution can lead to authentication bypass (boo#1209496) - CVE-2023-6681: denial of service Via specifically crafted JWE (boo#1219837) - CVE-2024-28102: malicious JWE token can cause denial of service (boo#1221230) - CVE-2026-39373: Memory exhaustion via crafted compressed JWE tokens (boo#1261802)
-
Release DateApr 16 2026
-
ReferencesBugzilla: 1219837, 1209496, 1221230, 1261802
CVEs: CVE-2022-3102, CVE-2023-6681, CVE-2024-28102, CVE-2026-39373 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Package Hub 15.7 x86_64
-
Packages
SUSE Package Hub 15.7 s390x
-
Packages
SUSE Package Hub 15.7 aarch64
-
Packages
SUSE Package Hub 15.7 ppc64le
-
Packages