CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in
CVSS
7.5
Alto
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 13 mar 2026 · Última mod.: 17 ago 2026 · CWE-345 · CWE-863 · CWE-347
0.3%EPSS · 30 días0.3%
2026-08-042026-08-31
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
- github.comhttps://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2026/05/msg00008.html
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10140
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10141
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10184
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:12176
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13508
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13512
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13545
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13553
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13672
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13916
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:17083
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19138
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19355
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19375
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19712
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21431
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21517
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22330
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-84355——
———Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)7hCVE-2026-84354——
———Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)7hCVE-2026-84335——
———Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)7hCVE-2026-84334——
———Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)7hCVE-2026-84332——
———Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)7hCVE-2026-84331——
———Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)7h