python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-09-23T06:55:09.000Z
Updated: 2024-08-03T12:00:43.537Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39227
Updated: 2024-08-03T12:00:43.537Z
Status : Modified
Published: 2022-09-23T07:15:09.300
Modified: 2024-11-21T07:17:49.730
Link: CVE-2022-39227