All vulnerabilities

CVE-2026-48522

PyPI · pyjwt

Summary

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

References