Fedora Account System
Red Hat Associate
Red Hat Customer
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:25902 https://access.redhat.com/errata/RHSA-2026:25902
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26206 https://access.redhat.com/errata/RHSA-2026:26206
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Via RHSA-2026:34160 https://access.redhat.com/errata/RHSA-2026:34160
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:35845 https://access.redhat.com/errata/RHSA-2026:35845
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:35836 https://access.redhat.com/errata/RHSA-2026:35836
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:35835 https://access.redhat.com/errata/RHSA-2026:35835
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:35837 https://access.redhat.com/errata/RHSA-2026:35837
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:50222 https://access.redhat.com/errata/RHSA-2026:50222
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:50223 https://access.redhat.com/errata/RHSA-2026:50223
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:50263 https://access.redhat.com/errata/RHSA-2026:50263
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2026:50319 https://access.redhat.com/errata/RHSA-2026:50319
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:50336 https://access.redhat.com/errata/RHSA-2026:50336