python3-pyjwt: Fix CVE-2026-48526

Reject JSON Web Key documents passed directly as HMAC secrets. This
prevents public asymmetric JWK data from being reused as an HMAC key
when an application permits mixed symmetric and asymmetric algorithms.

This patch applies the relevant subset of the upstream 2.13.0 fix.
The upstream commit is referenced in [1], and the public advisory is
referenced in [2].

[1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
[2] https://github.com/advisories/GHSA-xgmm-8j9v-c9wx

Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Hetvi Thakar
2026-08-12 09:35:12 +05:30
committed by Anuj Mittal
parent b9877579dc
commit 3c9dd88058
2 changed files with 88 additions and 0 deletions
@@ -10,6 +10,7 @@ SRC_URI += " \
file://CVE-2026-48522.patch \
file://CVE-2026-48524.patch \
file://CVE-2026-48525.patch \
file://CVE-2026-48526.patch \
"
SRC_URI[sha256sum] = "57e28d156e3d5c10088e0c68abb90bfac3df82b40a71bd0daa20c65ccd5c23de"