Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jpadilla — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting jpadilla. AI-powered Chinese analysis, POCs, and references for each vulnerability.

jpadilla develops security tools and research, focusing on web application security and vulnerability analysis. Their work commonly addresses remote code execution, cross-site scripting, and privilege escalation vulnerabilities across various platforms. With three CVEs recorded, jpadilla has demonstrated expertise in identifying flaws in authentication mechanisms and input validation processes. Their research often emphasizes practical exploitation techniques and defensive strategies, contributing to the broader security community. While no major public incidents are directly attributed to jpadilla, their CVE contributions highlight consistent engagement with identifying and documenting critical security weaknesses in widely-used software systems.

Top products by jpadilla: pyjwt
CVE ID Title CVSS Severity Published
CVE-2026-103001 PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse — pyjwt CWE-471 6.5 Medium 2026-09-30
CVE-2026-102265 PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header — pyjwt CWE-674 5.3 Medium 2026-09-28
CVE-2026-102275 PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion — pyjwt CWE-345 6.5 Medium 2026-09-28
CVE-2026-102274 PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set — pyjwt CWE-755 5.9 Medium 2026-09-28
CVE-2026-102273 PyJWT accepts public JWK containers as HMAC secrets — pyjwt CWE-347 7.4 High 2026-09-28
CVE-2026-102272 PyJWT BOM Bypass — pyjwt CWE-347 7.4 High 2026-09-28
CVE-2026-102271 PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard — pyjwt CWE-347 7.4 High 2026-09-28
CVE-2026-102270 PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. — pyjwt CWE-1333 4.4 Medium 2026-09-28
CVE-2026-102269 PyJWT: Non-canonical signature segments enable raw-token revocation bypass — pyjwt CWE-180 4.8 Medium 2026-09-28
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard — pyjwt CWE-347 9.1 Critical 2026-09-28
CVE-2026-102267 PyJWT: PyJWKClient follows redirects when fetching JWKS — pyjwt CWE-200 7.4 High 2026-09-28
CVE-2026-102266 PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation — pyjwt CWE-347 7.4 High 2026-09-28
CVE-2026-101918 PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False) — pyjwt CWE-248 5.3 Medium 2026-09-28
CVE-2026-101917 PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524) — pyjwt CWE-770 5.3 Medium 2026-09-28
CVE-2026-48525 PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS — pyjwt CWE-400 5.3 Medium 2026-05-28
CVE-2026-48523 PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys — pyjwt CWE-347 5.4 Medium 2026-05-28
CVE-2026-48526 PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed — pyjwt CWE-287 7.4 High 2026-05-28
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) — pyjwt CWE-460 3.7 Low 2026-05-28
CVE-2026-48522 PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes — pyjwt CWE-441 4.2 Medium 2026-05-28
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) — pyjwt CWE-345 7.5 High 2026-03-12
CVE-2024-53861 Issuer field partial matches allowed in pyjwt — pyjwt CWE-697 2.2 Low 2024-11-29
CVE-2022-29217 Key confusion through non-blocklisted public key formats in PyJWT — pyjwt CWE-327 7.4 High 2022-05-24

This page lists every published CVE security advisory associated with jpadilla. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.