{
  "@id": "urn:uuid:fcc54b3b-f234-4972-9956-73fe5a0230b5",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T07:35:00.185365+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post5+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post5+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    }
  ]
}
