{
  "@id": "urn:uuid:63a75bda-05a6-4752-a613-881f3ca5d9d5",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 6,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T15:57:50.734473+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:23:00.154863+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "action_statement": "Vulnerability CVE-2026-48522 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post2+tuxcare."
    }
  ]
}
