python-jose vulnerabilities
CVEs whose affected-version data names the python-jose package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-85394Critical· 9.1python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pa…
▾ Midnightmpdavis · python-joseEPSS 0.22%via NVD
CVE-2024-33663High· 7.4python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
▾ Twilightpython-jose · python-joseEPSS 0.31%via OSV