Skip to content

CVE-2025-61152 #391

@cmatos689

Description

@cmatos689

Hello python-jose team.

I open this issue as a way to try to confirm if CVE-2025-61152 has been officially recognized by you as a vulnerability affecting the python-jose code. The main reason behing my question is because the PoC seems to actually use an option that would cause the issue to arise in the first place (options={"verify_signature": False}), as identified in https://bugzilla.suse.com/show_bug.cgi?id=1251866#c5.

Thanks in advance for any information you are able to provide!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions