{"schema_version":"1.7.5","id":"SUSE-SU-2026:20839-1","published":"2026-03-25T18:08:28Z","modified":"2026-03-28T17:25:00.865021Z","related":["CVE-2026-32597"],"upstream":["CVE-2026-32597"],"summary":"Security update for python-PyJWT","details":"This update for python-PyJWT fixes the following issue:\n\nUpdate to PyJWT 2.12.1:\n\n- CVE-2026-32597: PyJWT accepts unknown `crit` header extensions (bsc#1259616).\n\nChangelog:\n\nUpdate to 2.12.1:\n\n - Add missing typing_extensions dependency for Python < 3.11 in\n   #1150\n\nUpdate to 2.12.0:\n\n - Annotate PyJWKSet.keys for pyright by @tamird in #1134\n - Close HTTPError response to prevent ResourceWarning on\n   Python 3.14 by @veeceey in #1133\n - Do not keep algorithms dict in PyJWK instances by @akx in\n   #1143\n - Use PyJWK algorithm when encoding without explicit\n   algorithm in #1148\n - Docs: Add PyJWKClient API reference and document the\n   two-tier caching system (JWK Set cache and signing key LRU\n   cache).\n\nUpdate to 2.11.0:\n\n - Enforce ECDSA curve validation per RFC 7518 Section 3.4.\n - Fix build system warnings by @kurtmckee in #1105\n - Validate key against allowed types for Algorithm family in\n   #964\n - Add iterator for JWKSet in #1041\n - Validate iss claim is a string during encoding and decoding\n   by @pachewise in #1040\n - Improve typing/logic for options in decode, decode_complete\n    by @pachewise in #1045\n - Declare float supported type for lifespan and timeout by\n   @nikitagashkov in #1068\n - Fix SyntaxWarnings/DeprecationWarnings caused by invalid\n   escape sequences by @kurtmckee in #1103\n - Development: Build a shared wheel once to speed up test\n   suite setup times by @kurtmckee in #1114\n - Development: Test type annotations across all supported\n   Python versions, increase the strictness of the type\n   checking, and remove the mypy pre-commit hook by @kurtmckee\n   in #1112\n - Support Python 3.14, and test against PyPy 3.10 and 3.11 by\n   @kurtmckee in #1104\n - Development: Migrate to build to test package building in\n   CI by @kurtmckee in #1108\n - Development: Improve coverage config and eliminate unused\n   test suite code by @kurtmckee in #1115\n - Docs: Standardize CHANGELOG links to PRs by @kurtmckee in\n   #1110\n - Docs: Fix Read the Docs builds by @kurtmckee in #1111\n - Docs: Add example of using leeway with nbf by @djw8605 in\n   #1034\n - Docs: Refactored docs with autodoc; added PyJWS and\n   jwt.algorithms docs by @pachewise in #1045\n - Docs: Documentation improvements for \"sub\" and \"jti\" claims\n   by @cleder in #1088\n - Development: Add pyupgrade as a pre-commit hook by\n   @kurtmckee in #1109\n - Add minimum key length validation for HMAC and RSA keys\n   (CWE-326). Warns by default via InsecureKeyLengthWarning\n   when keys are below minimum recommended lengths per RFC\n   7518 Section 3.2 (HMAC) and NIST SP 800-131A (RSA). Pass\n   enforce_minimum_key_length=True in options to PyJWT or\n   PyJWS to raise InvalidKeyError instead.\n - Refactor PyJWT to own an internal PyJWS instance instead of\n   calling global api_jws functions.\n","affected":[{"package":{"name":"python-PyJWT","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/python-PyJWT&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"python313-PyJWT":"2.12.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20839-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202620839-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259616"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32597"}]}