LinuxSecurity.com 06.05.2026 03:45 It was discovered that PyJWT, a Python implementation of JSON Web Token did not validate the crit Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.

Čítať celý článok >>