CVE-2025-45768: Weak Encryption
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45768?
CVE-2025-45768 has been assessed as a moderate severity vulnerability due to its weak encryption in pyjwt v2.10.1.
How do I fix CVE-2025-45768?
To fix CVE-2025-45768, update pyjwt to the latest version that addresses the encryption weakness.
What impact does CVE-2025-45768 have on my application?
CVE-2025-45768 could potentially allow unauthorized access to sensitive data due to its weak encryption implementation.
Which versions of pyjwt are affected by CVE-2025-45768?
CVE-2025-45768 affects pyjwt version 2.10.1 and possibly other versions with similar vulnerabilities.
Is there a patch for CVE-2025-45768?
Yes, a patch is available in the subsequent releases of pyjwt that enhance encryption strength.