{
  "@id": "urn:uuid:21f71666-703e-44e8-9a8b-9bf127aed611",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 8,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T14:56:54.506693+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      },
      "action_statement": "Vulnerability CVE-2022-29217 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T00:27:05.135813+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T01:08:30.473565+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:30:18.436677+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "action_statement": "Vulnerability CVE-2026-48525 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    }
  ]
}
