CVE-2026-48525
MediumAdvisory
Published 28 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.004
- 30th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 153
- of 17,781 indexed, latest versions
- Container images
- 157
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 157 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pyjwtpypi | 2.8.0, 2.9.0, 2.10.1, 2.11.0+2 more | 2.13.0 | 122 |
| pyjwtdeb | 1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 more | no fix listed | 37 |
- OSV records
- DEBIAN-CVE-2026-48525GHSA-w7vc-732c-9m39UBUNTU-CVE-2026-48525
- Also known as
- PYSEC-2026-178
Charts affected
153 by stars
Container images carrying it
157 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.