Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
PyJWT could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8133-1 March 30, 2026 pyjwt vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: PyJWT could allow unintended access to network services. Software Description: - pyjwt: Python 3 implementation of JSON Web Token Details: It was discovered that PyJWT did not validate the critical header parameter, contrary to the RFC specification expectations. A remote attacker could possibly use this issue to bypass certain authentication checks and restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-jwt 2.10.1-2ubuntu0.1 Ubuntu 24.04 LTS python3-jwt 2.7.0-1ubuntu0.1 Ubuntu 22.04 LTS python3-jwt 2.3.0-1ubuntu0.3 Ubuntu 20.04 LTS python3-jwt 1.7.1-2ubuntu2.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-jwt 1.5.3+ds1-1ubuntu0.1+esm1 Available with Ubuntu Pro python3-jwt 1.5.3+ds1-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS python-jwt 1.3.0-1ubuntu0.1+esm1 Available with Ubuntu Pro python3-jwt 1.3.0-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8133-1 CVE-2026-32597 Package Information: https://launchpad.net/ubuntu/+source/pyjwt/2.10.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/pyjwt/2.7.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/pyjwt/2.3.0-1ubuntu0.3 . PyJWT allows unintended access to network services on Ubuntu. Update to secure versions to protect systems.. PyJWT update, Ubuntu security, authentication vulnerability. . Severity: Important. LinuxSecurity.com Team
Ceph could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-7182-1 January 06, 2025 ceph vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Ceph could allow unintended access to network services. Software Description: - ceph: distributed storage and file system Details: It was discovered that Ceph incorrectly handled unsupported JWT algorithms in the RadosGW gateway. An attacker could possibly use this issue to bypass certain authentication checks and restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 ceph 19.2.0-0ubuntu2.1 ceph-base 19.2.0-0ubuntu2.1 ceph-common 19.2.0-0ubuntu2.1 radosgw 19.2.0-0ubuntu2.1 Ubuntu 24.04 LTS ceph 19.2.0-0ubuntu0.24.04.2 ceph-base 19.2.0-0ubuntu0.24.04.2 ceph-common 19.2.0-0ubuntu0.24.04.2 radosgw 19.2.0-0ubuntu0.24.04.2 Ubuntu 22.04 LTS ceph 17.2.7-0ubuntu0.22.04.2 ceph-base 17.2.7-0ubuntu0.22.04.2 ceph-common 17.2.7-0ubuntu0.22.04.2 radosgw 17.2.7-0ubuntu0.22.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7182-1 CVE-2024-48916 Package Information: https://launchpad.net/ubuntu/+source/ceph/19.2.0-0ubuntu2.1 . Kubernetes may expose services unexpectedly. Ensure you apply updates to your Debian systems for enhanced security against this vulnerability.. ceph security issue, unintended access, ubuntu advisory, network service vulnerability, software update instructions. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.