{"id":"SUSE-SU-2026:20879-1","summary":"Security update for python-PyJWT","details":"This update for python-PyJWT fixes the following issues:\n\nUpdate to PyJWT 2.12.1:\n\n- CVE-2024-53861: prevent partial matching of the Issuer field (bsc#1234038).\n- CVE-2026-32597: validate the crit Header Parameter defined in RFC 7515 (bsc#1259616).\n\nChangelog:\n\nUpdate to 2.12.1:\n\n - Add missing typing_extensions dependency for Python \u003c 3.11 in\n   #1150\n  \nUpdate to 2.12.0:\n\n - Annotate PyJWKSet.keys for pyright by @tamird in #1134\n - Close HTTPError response to prevent ResourceWarning on\n   Python 3.14 by @veeceey in #1133\n - Do not keep algorithms dict in PyJWK instances by @akx in\n   #1143\n - Use PyJWK algorithm when encoding without explicit\n   algorithm in #1148\n - Docs: Add PyJWKClient API reference and document the\n   two-tier caching system (JWK Set cache and signing key LRU\n   cache). \n\nUpdate to 2.11.0:\n \n - Enforce ECDSA curve validation per RFC 7518 Section 3.4.\n - Fix build system warnings by @kurtmckee in #1105\n - Validate key against allowed types for Algorithm family in\n   #964\n - Add iterator for JWKSet in #1041\n - Validate iss claim is a string during encoding and decoding\n   by @pachewise in #1040\n - Improve typing/logic for options in decode, decode_complete\n    by @pachewise in #1045\n - Declare float supported type for lifespan and timeout by\n   @nikitagashkov in #1068\n - Fix SyntaxWarnings/DeprecationWarnings caused by invalid\n   escape sequences by @kurtmckee in #1103\n - Development: Build a shared wheel once to speed up test\n   suite setup times by @kurtmckee in #1114\n - Development: Test type annotations across all supported\n   Python versions, increase the strictness of the type\n   checking, and remove the mypy pre-commit hook by @kurtmckee\n   in #1112\n - Support Python 3.14, and test against PyPy 3.10 and 3.11 by\n   @kurtmckee in #1104\n - Development: Migrate to build to test package building in\n   CI by @kurtmckee in #1108\n - Development: Improve coverage config and eliminate unused\n   test suite code by @kurtmckee in #1115\n - Docs: Standardize CHANGELOG links to PRs by @kurtmckee in\n   #1110\n - Docs: Fix Read the Docs builds by @kurtmckee in #1111\n - Docs: Add example of using leeway with nbf by @djw8605 in\n   #1034\n - Docs: Refactored docs with autodoc; added PyJWS and\n   jwt.algorithms docs by @pachewise in #1045\n - Docs: Documentation improvements for \"sub\" and \"jti\" claims\n   by @cleder in #1088\n - Development: Add pyupgrade as a pre-commit hook by\n   @kurtmckee in #1109\n - Add minimum key length validation for HMAC and RSA keys\n   (CWE-326). Warns by default via InsecureKeyLengthWarning\n   when keys are below minimum recommended lengths per RFC\n   7518 Section 3.2 (HMAC) and NIST SP 800-131A (RSA). Pass\n   enforce_minimum_key_length=True in options to PyJWT or\n   PyJWS to raise InvalidKeyError instead.\n - Refactor PyJWT to own an internal PyJWS instance instead of\n   calling global api_jws functions.\n  \nUpdate to 2.10.0:\n  \n * chore: use sequence for typing rather than list\n * Add support for Python 3.13\n * [pre-commit.ci] pre-commit autoupdate\n * Add an RTD config file to resolve RTD build failures\n * docs: Update iat exception docs\n * Remove algorithm requirement for JWT API\n * Create SECURITY.md\n * docs fix: decode_complete scope and algorithms\n * fix doctest for docs/usage.rst\n * fix test_utils.py not to xfail\n * Correct jwt.decode audience param doc expression\n * Add PS256 encoding and decoding usage\n * Add API docs for PyJWK\n * Refactor project configuration files from setup.cfg to pyproject.toml PEP-518\n * Add JWK support to JWT encode\n * Update pre-commit hooks to lint pyproject.toml\n * Add EdDSA algorithm encoding/decoding usage\n * Ruff linter and formatter changes\n * Validate sub and jti claims for the token\n * Add ES256 usage\n * Encode EC keys with a fixed bit length\n * Drop support for Python 3.8\n * Prepare 2.10.0 release\n * Bump codecov/codecov-action from 4 to 5\n","modified":"2026-03-31T17:23:51.868780Z","published":"2026-03-26T08:57:07Z","related":["CVE-2024-53861","CVE-2026-32597"],"upstream":["CVE-2024-53861","CVE-2026-32597"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202620879-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259616"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-53861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32597"}],"affected":[{"package":{"name":"python-PyJWT","ecosystem":"SUSE:Linux Micro 6.1","purl":"pkg:rpm/suse/python-PyJWT&distro=SUSE%20Linux%20Micro%206.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.1-slfo.1.1_1.1"}]}],"ecosystem_specific":{"binaries":[{"python311-PyJWT":"2.12.1-slfo.1.1_1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20879-1.json"}}],"schema_version":"1.7.5"}