Amazon Linux 2023 Security Advisory: ALAS2023-2026-1842
Advisory Released Date: 2026-06-22
Advisory Updated Date: 2026-06-22
Severity:
Important
Issue Overview:
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0. (CVE-2026-48526)
Affected Packages:
python-jwt
Issue Correction:
Run dnf update python-jwt --releasever 2023.12.20260622 or dnf update --advisory ALAS2023-2026-1842 --releasever 2023.12.20260622 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
noarch:
python3-jwt+crypto-2.4.0-1.amzn2023.0.4.noarch
python3-jwt-2.4.0-1.amzn2023.0.4.noarch
src:
python-jwt-2.4.0-1.amzn2023.0.4.src