CVE-2026-48525
MediumAdvisory
Published 28 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.004
- 30th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 153
- of 17,781 indexed, latest versions
- Container images
- 157
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 157 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pyjwtpypi | 2.8.0, 2.9.0, 2.10.1, 2.11.0+2 more | 2.13.0 | 122 |
| pyjwtdeb | 1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 more | no fix listed | 37 |
- OSV records
- DEBIAN-CVE-2026-48525GHSA-w7vc-732c-9m39UBUNTU-CVE-2026-48525
- Also known as
- PYSEC-2026-178
Charts affected
153 by stars
Container images carrying it
157 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| intelowlproject/ | 0b22e547ea6b | pyjwt | 2.13.0 | 1 |
| juicedata/ | 95008ba63318 | pyjwt | no fix listed | 1 |
| jupyterhub/ | 5a0ceed1300a | pyjwt | 2.13.0 | 1 |
| kenchrcum/ | c326e28a8f5f | pyjwt | 2.13.0 | 1 |
| langgenius/ | 066035f93856 | pyjwt | 2.13.0 | 1 |
| langgenius/ | fca918260dd6 | pyjwt | 2.13.0 | 1 |
| linuxserver/ | 4477fb1ce3ca | pyjwt | 2.13.0 | 1 |
| litellm/ | 09b217802ded | pyjwt | 2.13.0 | 1 |
| louislam/ | 059b49d64739 | pyjwt | no fix listed | 1 |
| louislam/ | 3e24e96c89ef | pyjwt | no fix listed | 1 |
| louislam/ | 4c364ef96aad | pyjwt | no fix listed | 1 |
| louislam/ | 91e963bfda56 | pyjwt | no fix listed | 1 |
| louislam/ | 9865163f92c1 | pyjwt | no fix listed | 1 |
| mawad98/ | 99422c56a274 | pyjwt | 2.13.0 | 1 |
| memgraph/ | ecdf7faea3f7 | pyjwt | 2.13.0 | 1 |
| mindsdb/ | 163011c09299 | pyjwt | 2.13.0 | 1 |
| mintproject/ | 02260d20a21f | pyjwt | 2.13.0 | 1 |
| mozilla/ | 93752877dced | pyjwt | 2.13.0 | 1 |
| netboxcommunity/ | 91b823a05cb5 | pyjwt | 2.13.0 | 1 |
| netboxcommunity/ | 9bf83b350a89 | pyjwt | 2.13.0 | 1 |
| networktocode/ | ed484336b1ad | pyjwt | 2.13.0 | 1 |
| opencsghq/ | 2f03fead54db | pyjwt | 2.13.0 | 1 |
| opencsghq/ | af7191a9cf8a | pyjwt | 2.13.0 | 1 |
| opencsghq/ | c36a5bac3cf0 | pyjwt | 2.13.0 | 1 |
| opencsghq/ | 47e22aa71870 | pyjwt | 2.13.0 | 1 |
| opencsghq/ | b4e849fcf94a | pyjwt | 2.13.0 | 1 |
| openmined/ | b72f74a68b32 | pyjwt | 2.13.0 | 1 |
| pangeo/ | 5fbe688a4f80 | pyjwt | 2.13.0 | 1 |
| qonstrukt/ | 089af7925aa1 | pyjwt | no fix listed | 1 |
| salehmir/ | 1afa95f979e9 | pyjwt | 2.13.0 | 1 |
| seafileltd/ | d0c66e4621bd | pyjwt | no fix listed | 1 |
| sirrend/ | 699e79e3d4e2 | pyjwt | 2.13.0 | 1 |
| sirrend/ | 7ca688c7abf5 | pyjwt | 2.13.0 | 1 |
| timescale/ | a8e3322e1cf9 | pyjwt | no fix listed | 1 |
| timescale/ | cdb9ae118899 | pyjwt | no fix listed | 1 |
| timescale/ | d7db8f1085a3 | pyjwt | no fix listed | 1 |
| timescale/ | e8d0a9cc3db5 | pyjwt | no fix listed | 1 |
| timescale/ | ed719c0cd19d | pyjwt | no fix listed | 1 |
| tombursch/ | b48e4ab727cd | pyjwt | 2.13.0 | 1 |
| trueosiris/ | 9356f98ad561 | pyjwt | no fix listed | 1 |
| twentycrm/ | 2f78405a78be | pyjwt | no fix listed | 1 |
| vabene1111/ | 0f8d061895e9 | pyjwt | 2.13.0 | 1 |
| wazuh/ | 1da5c38c6a78 | pyjwt | 2.13.0 | 1 |
| wazuh/ | 5a065930682d | pyjwt | 2.13.0 | 1 |
| wazuh/ | f09282d281f6 | pyjwt | 2.13.0 | 1 |
| yetiplatform/ | 9bcbe2650a14 | pyjwt | 2.13.0 | 1 |
| yetiplatform/ | 9c3006cedcca | pyjwt | 2.13.0 | 1 |
| zepai/ | 6ab0ee79926b | pyjwt | 2.13.0 | 1 |
| zooproject/ | 9a507cb7e2dd | pyjwt | no fix listed | 1 |
| gcr.io/ | a534a3170d03 | pyjwt | 2.13.0 | 1 |