CVE-2026-32597

Aliases:GHSA-752w-5fwx-jx9fECHO-b1a0-3286-88daPYSEC-2026-120DEBIAN-CVE-2026-32597CGA-24hm-25v5-wmfqCGA-25w2-2w29-77q3CGA-279c-35vp-4f8hCGA-3gcg-366r-qpf9CGA-3gh2-39vx-fwxgCGA-482p-f9v7-qh3wCGA-4g76-8h5f-wmx4CGA-528c-7964-w6gpCGA-6hp8-qfm7-qrjmCGA-6qxw-4j9v-jqv9CGA-72mg-m2hw-x6cvCGA-7pjw-qmjp-hm84CGA-7x39-668x-695hCGA-84wm-98w4-gpv3CGA-9hvg-hm5w-4qwjCGA-c59r-2g94-v2chCGA-cw99-xc4g-8fxrCGA-fvwq-frf5-337jCGA-gw32-hcv4-h29cCGA-h275-49j5-pgq8CGA-h29m-8q8g-wq75CGA-hgv8-7f6m-4v62CGA-hq63-jw5m-8vjmCGA-m88j-49ff-w6g6CGA-mrj5-g5g4-3wjmCGA-2fv9-r6jf-58cmCGA-2wvq-f7xf-x2gvCGA-2xp2-5hm2-8gpmCGA-43w9-phhj-9x8hCGA-49jj-r8h2-xj37CGA-4fqc-m97v-m22vCGA-59v6-3j37-w94hCGA-59vr-rv5r-2cvqCGA-5fc9-44r7-p2f4CGA-64cf-cp36-ghvcCGA-684r-2c87-fvfxCGA-6rvf-5mxv-3ccrCGA-7hr8-8355-4ccwCGA-7v6p-x7xc-c92xCGA-7w5q-cmjp-58fvCGA-82q3-rhhw-vw5cCGA-8p96-8wfr-7rhmCGA-8q7w-3h5j-73vvCGA-9267-c9c5-wj85CGA-9g25-j6qx-249hCGA-9gjv-754c-5x43CGA-cpj3-gf3r-gx3xCGA-cw9g-p4q3-55hvCGA-cx3q-44g5-xf2pCGA-f2q8-xrx3-7jwhCGA-f34f-wqxq-w53rCGA-f7hw-xph9-hhmrCGA-fr68-3jrx-jqjrCGA-fw7c-9ppm-f9r9CGA-g2p6-48g8-w7f8CGA-g4qv-wp6q-xxw2CGA-gph2-x4vh-x25qCGA-gqh4-qrg2-5pfxCGA-grh4-3qg5-5wj5CGA-h57v-x55g-c9rgCGA-hg4c-jfgx-5mrcCGA-hmc7-h2p9-xcf5CGA-hq4c-g857-vhm9CGA-j33f-q45f-9j35CGA-pg3v-64g7-5vg8CGA-phq8-x9vg-j27cCGA-pmj2-cm3c-9mwvCGA-pxv3-3f98-55f5CGA-q6mx-j7vw-32fvCGA-qw6p-9v3g-xrm4CGA-rgpm-rwpw-47w7CGA-rhg4-c9fx-qf6mCGA-rq29-gqq8-hqpqCGA-v6g3-qg8m-r26qCGA-v6vx-772m-6fvmCGA-vjqm-4vrh-642xCGA-vrjf-qrgw-46x6CGA-w9cp-xj5j-cpppCGA-x6qq-q3mm-4jmrCGA-xgvv-64qq-cg83CGA-xmh2-m6cx-vwx5CGA-8qmg-wvf6-jfq9
Modified
Published: 12 Mar 2026, 21:41
Last modified:10 Sept 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.27% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

12 Mar 2026, 21:41
Published
Vulnerability first disclosed
10 Sept 2026, 12:05
Last Modified
Vulnerability information updated

Description

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.27% Percentile: 19%

Techniques & Countermeasures

  • CWE-345Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-347Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Systems

  • chainguardairflow-2

    < 2.11.2-r2

  • chainguardairflow-3

    < 3.1.8-r8

  • chainguardairflow-core-2

    < 2.11.2-r1

  • chainguardairflow-core-3

    < 3.1.8-r1

  • chainguardauthentik

    < 2026.2.1-r4

  • chainguardauthentik-fips

    < 2026.2.1-r3

  • chainguardawx

    < 24.6.1-r31

  • chainguardaz

    < 2.84.0-r3

  • chainguarddatadog-agent-7.71-core-integrations

    all

  • chainguarddatadog-agent-7.72-core-integrations

    all

  • chainguarddatadog-agent-7.73-core-integrations

    < 7.73.3-r23

  • chainguarddatadog-agent-7.74-core-integrations

    < 7.74.1-r24

  • chainguarddatadog-agent-7.75-core-integrations

    all

  • chainguarddatadog-agent-7.76

    < 7.76.3-r41

  • chainguarddatadog-agent-7.76-core-integrations

    < 7.76.3-r26

  • chainguarddatadog-agent-fips-7.71-core-integrations

    all

  • chainguarddatadog-agent-fips-7.72-core-integrations

    all

  • chainguarddatadog-agent-fips-7.73-core-integrations

    < 7.73.3-r21

  • chainguarddatadog-agent-fips-7.74-core-integrations

    < 7.74.1-r26

  • chainguarddatadog-agent-fips-7.75-core-integrations

    all

  • chainguarddatadog-agent-fips-7.76-core-integrations

    < 7.76.3-r24

  • chainguarddbt-snowflake

    < 1.10.4-r2

  • chainguardggshield

    < 1.49.0-r1 | < 1.49.0-r2

  • chainguardkeep-api

    < 0.51.0-r0

  • chainguardkeep-api-fips

    < 0.51.0-r0

  • chainguardkserve-storage-controller

    < 0.16.0-r22

  • chainguardlabel-studio

    < 1.23.0-r0

  • chainguardlitellm

    < 1.82.3.0-r0

  • chainguardmetaflow-service-fips

    < 2.5.0-r1

  • chainguardopal

    < 0.9.3-r3

  • chainguardopen-webui

    < 0.8.10-r1

  • chainguardpgadmin4-fips

    < 9.13-r1

  • chainguardpy3-cassandra-medusa

    < 0.27.0-r5

  • chainguardpy3-semgrep

    < 1.156.0-r0

  • chainguardpy3.13-duplicity

    all

  • chainguardrequest-1276

    < 0.27.0-r6

  • chainguardsuperset-5.0

    < 5.0.0-r20

  • chainguardsuperset-6.0

    < 6.0.0-r4

  • chainguardvllm-openai-cuda-12.9

    < 0.17.1-r1

  • wolfiairflow-3

    < 3.1.8-r8

  • wolfiaz

    < 2.84.0-r3

  • wolfidatadog-agent-7.72-core-integrations

    all

  • wolfidatadog-agent-7.73-core-integrations

    < 7.73.3-r23

  • wolfidatadog-agent-7.74-core-integrations

    < 7.74.1-r24

  • wolfidatadog-agent-7.75-core-integrations

    all

  • wolfidatadog-agent-7.76

    < 7.76.3-r41

  • wolfidatadog-agent-7.76-core-integrations

    < 7.76.3-r26

  • wolfiggshield

    < 1.49.0-r1 | < 1.49.0-r2

  • wolfikserve-storage-controller

    < 0.16.0-r22

  • wolfiopen-webui

    < 0.8.10-r1

Showing first 50 affected entries in server-rendered view.

References (40)