Vulnerability Description
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pyjwt Project | Pyjwt | 2.10.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/ZupeiNie/6f65e564f2067b876321d3dfdbb76569Issue Tracking
- https://github.com/jpadillaProduct
- https://github.com/jpadilla/pyjwtProduct
FAQ
What is CVE-2025-45768?
CVE-2025-45768 is a vulnerability with a CVSS score of 7.0 (HIGH). pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may...
How severe is CVE-2025-45768?
CVE-2025-45768 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45768?
Check the references section above for vendor advisories and patch information. Affected products include: Pyjwt Project Pyjwt.