CVE Vulnerabilities

CVE-2026-32597

Insufficient Verification of Data Authenticity

Published: Mar 13, 2026 | Modified: May 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
PyjwtPyjwt_project*2.12.0 (excluding)
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatautomation-controller-0:4.6.28-3.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatpython3.12-pyjwt-0:2.12.1-1.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatautomation-controller-0:4.6.28-3.el9ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatpython3.12-pyjwt-0:2.12.1-1.el9ap*
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatautomation-controller-0:4.7.11-2.el9ap*
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatpython3.12-pyjwt-0:2.12.1-1.el9ap*
Red Hat Enterprise Linux 10RedHatfence-agents-0:4.16.0-13.el10_1.4*
Red Hat Enterprise Linux 10RedHatfence-agents-0:4.16.0-21.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatfence-agents-0:4.16.0-5.el10_0.9*
Red Hat Enterprise Linux 8RedHatfence-agents-0:4.2.1-129.el8_10.25*
Red Hat Enterprise Linux 9RedHatfence-agents-0:4.10.0-98.el9_7.12*
Red Hat Enterprise Linux 9RedHatfence-agents-0:4.10.0-110.el9_8.2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatfence-agents-0:4.10.0-43.el9_2.21*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatfence-agents-0:4.10.0-62.el9_4.24*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatfence-agents-0:4.10.0-86.el9_6.16*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-cuda-rhel9:1775680192*
Red Hat AI Inference Server 3.3RedHatrhaiis/vllm-rocm-rhel9:1775680262*
Red Hat AI Inference Server 3.3RedHatrhaiis/model-opt-cuda-rhel9:1775749857*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/gateway-rhel8:1777394109*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/lightspeed-rhel8:1777403872*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/eda-controller-rhel9:1777296732*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/ee-supported-rhel9:1777391447*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/gateway-rhel9:1777311120*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/hub-rhel9:1777299023*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/lightspeed-chatbot-rhel9:1777398576*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/lightspeed-rhel9:1777387242*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/mcp-tools-rhel9:1777311601*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-aws-cuda-rhel9:1776871984*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-azure-cuda-rhel9:1776871985*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-azure-rocm-rhel9:1776872005*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-cuda-rhel9:1776773390*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-gcp-cuda-rhel9:1776871987*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-rocm-rhel9:1776773505*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/disk-image-cuda-rhel9:1776938871*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-feature-server-rhel9:1776338381*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-kserve-storage-initializer-rhel9:1776343111*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-vllm-gaudi-rhel9:1780069069*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-vllm-cpu-rhel9:1778264363*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-vllm-gaudi-rhel9:1778600187*
Red Hat Quay 3.1RedHatquay/quay-rhel8:1775169155*
Red Hat Quay 3.12RedHatquay/quay-rhel8:1775253092*
Red Hat Quay 3.15RedHatquay/quay-rhel8:1775169219*
Red Hat Quay 3.16RedHatquay/quay-rhel9:1779204086*
Red Hat Quay 3.9RedHatquay/quay-rhel8:1775169218*
Red Hat Satellite 6.18RedHatsatellite/iop-host-inventory-rhel9:1780414237*
Red Hat Trusted Artifact Signer 1.4RedHatrhtas/model-transparency-rhel9:1775815407*
PyjwtUbuntuesm-infra-legacy/xenial*
PyjwtUbuntuesm-infra/bionic*
PyjwtUbuntuesm-infra/focal*
PyjwtUbuntuesm-infra/xenial*
PyjwtUbuntujammy*
PyjwtUbuntunoble*
PyjwtUbuntuquesting*

References