REDHAT-BUG-2447194: High severity pypi/pyjwt vulnerability
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PyJWTto a version that resolves this vulnerability.Fixed in 2.12.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2447194?
The severity of REDHAT-BUG-2447194 is high, rated at 7.
How do I fix REDHAT-BUG-2447194?
To fix REDHAT-BUG-2447194, upgrade PyJWT to version 2.12.0 or later.
What does REDHAT-BUG-2447194 affect?
REDHAT-BUG-2447194 affects the PyJWT library used for JSON Web Token implementation in Python.
What are the implications of REDHAT-BUG-2447194?
The implications of REDHAT-BUG-2447194 include potential security issues since PyJWT accepts tokens with unrecognized crit parameters.
When was REDHAT-BUG-2447194 published?
REDHAT-BUG-2447194 was published on March 12, 2026.