python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 19:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-85394
Mitre link : CVE-2026-85394
CVE.ORG link : CVE-2026-85394
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature
