This update for python-jwcrypto fixes the following issues:
- CVE-2022-3102: jwcrypto token substitution can lead to authentication
bypass (boo#1209496)
- CVE-2023-6681: denial of service Via specifically crafted JWE
(boo#1219837)
- CVE-2024-28102: malicious JWE token can cause denial of service
(boo#1221230)
- CVE-2026-39373: Memory exhaustion via crafted compressed JWE tokens
(boo#1261802)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-129=1
- openSUSE Backports SLE-15-SP7 (noarch):
python3-jwcrypto-0.7-bp157.2.3.1
https://www.suse.com/security/cve/CVE-2022-3102.html
https://www.suse.com/security/cve/CVE-2023-6681.html
https://www.suse.com/security/cve/CVE-2024-28102.html
https://www.suse.com/security/cve/CVE-2026-39373.html
https://bugzilla.suse.com/1209496
https://bugzilla.suse.com/1219837
https://bugzilla.suse.com/1221230
https://bugzilla.suse.com/1261802
Get the latest Linux and open source security news straight to your inbox.