PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64url_decode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.
The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pyjwt | Pyjwt_project | * | 2.14.0 (excluding) |
| Pyjwt | Ubuntu | upstream | * |