Weak Encryption in pyjwt v2.10.1 from Vendor jpadilla
CVE-2025-45768
7HIGH
What is CVE-2025-45768?
The pyjwt v2.10.1 version has been identified with a vulnerability that allows weak encryption standards to be utilized, which could compromise the security of tokens generated using this library. This vulnerability may expose sensitive information and undermine the integrity of authentication processes in applications relying on this library for JSON Web Tokens (JWT). Immediate action is recommended to mitigate potential risks associated with this weakness.
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
