mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-22 11:00:49 +00:00
python3-pyjwt: Fix CVE-2026-48525
Reject a non-empty compact payload segment for b64=false tokens before Base64URL decoding. The segment is unused for detached JWS verification, so decoding it allowed unauthenticated CPU and memory consumption. This patch applies the relevant subset of the upstream 2.13.0 fix. The upstream commit is referenced in [1], and the public advisory is referenced in [2]. [1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 [2] https://github.com/advisories/GHSA-w7vc-732c-9m39 Signed-off-by: Hetvi Thakar <hthakar@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
@@ -9,6 +9,7 @@ SRC_URI += " \
|
||||
file://CVE-2026-32597.patch \
|
||||
file://CVE-2026-48522.patch \
|
||||
file://CVE-2026-48524.patch \
|
||||
file://CVE-2026-48525.patch \
|
||||
"
|
||||
SRC_URI[sha256sum] = "57e28d156e3d5c10088e0c68abb90bfac3df82b40a71bd0daa20c65ccd5c23de"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user