mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-01 16:10:25 +00:00
Reject a non-empty compact payload segment for b64=false tokens before Base64URL decoding. The segment is unused for detached JWS verification, so decoding it allowed unauthenticated CPU and memory consumption. This patch applies the relevant subset of the upstream 2.13.0 fix. The upstream commit is referenced in [1], and the public advisory is referenced in [2]. [1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 [2] https://github.com/advisories/GHSA-w7vc-732c-9m39 Signed-off-by: Hetvi Thakar <hthakar@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>