Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2249276
AlmaLinux
5974
Alpaquita
16105
Alpine
4618
Android
2912
Azure Linux
17673
BellSoft Hardened Containers
754
Bitnami
9341
Chainguard
1030980
CleanStart
3946
CRAN
14
crates.io
2739
Debian
68604
Docker Hardened Images
1
Echo
4006
GHC
3
GIT
107156
GitHub Actions
55
Go
9247
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6232
Maven
7046
MinimOS
145440
npm
229015
NuGet
1869
opam
29
openEuler
8800
openSUSE
14484
OSS-Fuzz
4003
Packagist
7106
Pub
11
PyPI
25211
Red Hat
23413
Rocky Linux
4317
Root
19604
RubyGems
5326
SUSE
23360
SwiftURL
60
TuxCare
9676
Ubuntu
65638
VSCode
21
Wolfi
333108
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-42vr-xj54-vc7v
PyPI/pyjwt
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
1 hour ago
Fix available
Severity - 5.3 (Medium)
GHSA-gh4c-6fx4-qh6g
PyPI/urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
2 hours ago
Fix available
Severity - 6.9 (Medium)
GHSA-vxq7-64xx-v4gw
PyPI/urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
2 hours ago
Fix available
Severity - 8.9 (High)
GHSA-8988-9cw3-xx77
PyPI/urllib3
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
2 hours ago
Fix available
Severity - 7.6 (High)
GHSA-jwrc-g2q2-pq5p
PyPI/pyjwt
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
2 hours ago
Fix available
Severity - 4.4 (Medium)
MAL-2026-17325
PyPI/cleanup-string
Malicious code in cleanup-string (PyPI)
12 hours ago
No fix available
MAL-2026-17319
PyPI/bfox-build-utils
Malicious code in bfox-build-utils (PyPI)
14 hours ago
No fix available
GHSA-9j54-fg26-wv3r
PyPI/pyjwt
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
17 hours ago
Fix available
Severity - 7.4 (High)
GHSA-8wjv-2p76-3863
PyPI/pyjwt
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
17 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-hxm8-2xgr-2p9m
PyPI/pyjwt
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
17 hours ago
Fix available
Severity - 4.8 (Medium)
GHSA-ffc3-869f-jxw9
PyPI/pyjwt
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
17 hours ago
Fix available
Severity - 9.1 (Critical)
GHSA-w2cx-738m-mc7w
PyPI/pyjwt
PyJWT accepts public JWK containers as HMAC secrets
17 hours ago
Fix available
Severity - 7.4 (High)
GHSA-9v7f-9g4p-ffgj
PyPI/pyjwt
PyJWT: PyJWKClient follows redirects when fetching JWKS
17 hours ago
Fix available
Severity - 7.4 (High)
GHSA-p4g4-x82p-q773
PyPI/pyjwt
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
17 hours ago
Fix available
Severity - 7.4 (High)
GHSA-r6x4-923q-g947
PyPI/pyjwt
PyJWT BOM Bypass
17 hours ago
Fix available
Severity - 7.4 (High)
GHSA-2gx3-rcp4-g85q
PyPI/pyjwt
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
17 hours ago
Fix available
Severity - 5.3 (Medium)
Load more...
PyPI - OSV