fix(deps): update dependency pyjwt to v2 (main) - #364
Open
mend-for-github-com[bot] wants to merge 1 commit into
Open
mend-for-github-com[bot] wants to merge 1 commit into
mend-for-github-com[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=1.6.4→>=2.15.0By merging this PR, the below vulnerabilities will be automatically resolved:
Release Notes
jpadilla/pyjwt (pyjwt)
v2.15.0Compare Source
Fixed
DecodeErrorinstead of exposing a raw
RecursionError.Added
JWKSetCachenow stores the parsedPyJWKSetrather than the raw JWKSpayload, so a cache hit no longer re-parses every key.
JWKSetCache.put()accepts either form and raises
PyJWKSetErrorfor anything else. As aresult,
PyJWKClient.get_jwk_set()returns the samePyJWKSetinstancefor as long as it stays cached, rather than a freshly built one per call in
#​1208 <https://github.com/jpadilla/pyjwt/pull/1208>__PyJWKClient.fetch_data()now raisesPyJWKClientError("The JWKS endpoint did not return a JSON object")whenthe endpoint response is not a JSON object, instead of returning it for
get_jwk_set()to reject. Callers reaching the JWKS throughget_jwk_set()see the same error as before in#​1208 <https://github.com/jpadilla/pyjwt/pull/1208>__Fixed
JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>,GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>,GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>,and
GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>.PyJWKClientfetches a JWKS, preventingredirected destinations from being treated as trusted key sources. See
GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>__.normal key-rotation behavior. See
GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>__.errors or whole-set parsing failures. See
GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>__and
GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>__.GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>__.@xclow3n <https://github.com/xclow3n>__ for reporting this behavior; fixed in commit37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>__.Fixed
HMACAlgorithm.prepare_keyto close an algorithm-confusion gap thatthe existing PEM/SSH guard did not cover. Reported by @aradona91 in
GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>__.algtoPyJWK.algorithm_nameduringverification so the caller's
algorithms=[...]allow-list cannot bebypassed when decoding with a
PyJWK/PyJWKClientkey. Reportedby @sushi-gif in
GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>__.http(s)URI schemes inPyJWKClientso attacker-influenced URIs cannot read local files or reach unintended schemes via
urllib's default
file:///ftp:///data:handlers. Reportedby @KEIJOT in
GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>__.PyJWKClient.fetch_data.The previous
finally-blockput(None)pattern cleared the cacheon any transient outage, turning one bad JWKS request into application-
wide auth failure. Reported by @eddieran in
GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>__.when
b64=falseis set in the protected header, and require thatsegment to be empty (RFC 7515 Appendix F detached form). Closes an
unauthenticated DoS amplifier. Reported by @thesmartshadow in
GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>__.Fixed
dev,docs, andtestspackage extras to dependency groups by @kurtmckee in#​1152 <https://github.com/jpadilla/pyjwt/pull/1152>__v2.14.0Compare Source
See the 2.14.0 changelog for the complete release details and related security advisories.
v2.13.0Compare Source
PyJWT 2.13.0 — Security Release
This release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.
Security
GHSA-xgmm-8j9v-c9wx— JWK JSON accepted as HMAC secret (algorithm confusion).HMACAlgorithm.prepare_keypreviously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms inalgorithms=[…]and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. Reported by @aradona91.GHSA-jq35-7prp-9v3f— Algorithm allow-list bypass withPyJWK/PyJWKClient. When verifying with aPyJWK, the caller'salgorithms=[…]allow-list was checked against the token headeralgas a string only; actual verification used the algorithm bound to thePyJWK. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token headeralgto match thePyJWK's algorithm before verification. Reported by @sushi-gif.GHSA-w7vc-732c-9m39— DoS via base64 decode of unused payload segment whenb64=false. For detached-payload JWS (b64=false), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplieddetached_payload. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. Reported by @thesmartshadow.GHSA-993g-76c3-p5m4—PyJWKClientaccepts non-HTTP(S) URIs.PyJWKClient.fetch_datapassed its URI tourllib.request.urlopen, which by default also handlesfile://,ftp://, anddata:schemes. An application that fed an attacker-influenced URI intoPyJWKClientcould be coerced into reading local files or reaching other unintended schemes.PyJWKClientnow rejects any URI whose scheme isn'thttporhttps. Reported by @KEIJOT.GHSA-fhv5-28vv-h8m8—PyJWKClientcache wiped on fetch error. Afinally-blockput(jwk_set=None)cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. Reported by @eddieran.Fixed
HMACAlgorithm.prepare_keywithInvalidKeyErrorinstead of accepting them with only a warning. Defends against theos.getenv("JWT_SECRET", "")footgun. Thanks to @SnailSploit and @spartan8806 for the reports.options(includingenforce_minimum_key_length) fromPyJWT.decodethrough toPyJWS._verify_signature. The option was previously silently dropped between the two layers, so it only took effect when set on thePyJWTinstance. Thanks to @WLUB for the report.b64=false: the encoder now auto-adds"b64"tocrit, and the decoder rejects tokens that setb64=falsewithout listing it incrit. Thanks to @MachineLearning-Nerd for the report.Changed
dev,docs, andtestspackage extras to dependency groups, by @kurtmckee in #1152.Upgrade notes
Most fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:
""orb""as a secret (often via a missing env var, e.g.os.getenv("JWT_SECRET", "")),encode/decodewill now raiseInvalidKeyError. This is the intended behavior — fix the configuration.PyJWKdecoding now requires the token'salgto match the JWK's algorithm. Previously a mismatch was silently honored if the headeralgappeared in the allow-list. Tokens that relied on this mismatch will now fail withInvalidAlgorithmError.PyJWKClientnow rejects non-HTTP(S) URIs at construction time. Tests or dev environments that fetched JWKS fromfile://URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. constructPyJWKSet.from_dict(...)directly).b64=falsetokens are now strictly RFC 7515 / 7797 compliant. Tokens with a non-empty compact-form payload segment, or that omit"b64"fromcrit, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.enforce_minimum_key_lengthset per-call now takes effect. Callers who passedoptions={"enforce_minimum_key_length": True}tojwt.decode()previously got no enforcement; they will now getInvalidKeyErroron undersized keys, as documented.Full changelog: jpadilla/pyjwt@2.12.1...2.13.0
v2.12.1Compare Source
Fixed
#​1134 <https://github.com/jpadilla/pyjwt/pull/1134>__HTTPErrorresponse to preventResourceWarningon Python 3.14 by @veeceey in#​1133 <https://github.com/jpadilla/pyjwt/pull/1133>__algorithmsdict in PyJWK instances by @akx in#​1143 <https://github.com/jpadilla/pyjwt/pull/1143>__GHSA-752w-5fwx-jx9f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f>__#​1148 <https://github.com/jpadilla/pyjwt/pull/1148>__Added
#​1105 <https://github.com/jpadilla/pyjwt/pull/1105>__#​964 <https://github.com/jpadilla/pyjwt/pull/964>__#​1041 <https://github.com/jpadilla/pyjwt/pull/1041>__issclaim is a string during encoding and decoding by @pachewise in#​1040 <https://github.com/jpadilla/pyjwt/pull/1040>__optionsin decode, decode_complete by @pachewise in#​1045 <https://github.com/jpadilla/pyjwt/pull/1045>__#​1068 <https://github.com/jpadilla/pyjwt/pull/1068>__SyntaxWarning\s/DeprecationWarning\s caused by invalid escape sequences by @kurtmckee in#​1103 <https://github.com/jpadilla/pyjwt/pull/1103>__#​1114 <https://github.com/jpadilla/pyjwt/pull/1114>__increase the strictness of the type checking, and remove the mypy pre-commit hook
by @kurtmckee in
#​1112 <https://github.com/jpadilla/pyjwt/pull/1112>__Added
issclaim by @fabianbadoi inGHSA-75c5-xw7c-p5pm <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-75c5-xw7c-p5pm>__v2.12.0Compare Source
Fixed
#​1134 <https://github.com/jpadilla/pyjwt/pull/1134>__HTTPErrorresponse to preventResourceWarningon Python 3.14 by @veeceey in#​1133 <https://github.com/jpadilla/pyjwt/pull/1133>__algorithmsdict in PyJWK instances by @akx in#​1143 <https://github.com/jpadilla/pyjwt/pull/1143>__GHSA-752w-5fwx-jx9f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f>__#​1148 <https://github.com/jpadilla/pyjwt/pull/1148>__Added
#​1105 <https://github.com/jpadilla/pyjwt/pull/1105>__#​964 <https://github.com/jpadilla/pyjwt/pull/964>__#​1041 <https://github.com/jpadilla/pyjwt/pull/1041>__issclaim is a string during encoding and decoding by @pachewise in#​1040 <https://github.com/jpadilla/pyjwt/pull/1040>__optionsin decode, decode_complete by @pachewise in#​1045 <https://github.com/jpadilla/pyjwt/pull/1045>__#​1068 <https://github.com/jpadilla/pyjwt/pull/1068>__SyntaxWarning\s/DeprecationWarning\s caused by invalid escape sequences by @kurtmckee in#​1103 <https://github.com/jpadilla/pyjwt/pull/1103>__#​1114 <https://github.com/jpadilla/pyjwt/pull/1114>__increase the strictness of the type checking, and remove the mypy pre-commit hook
by @kurtmckee in
#​1112 <https://github.com/jpadilla/pyjwt/pull/1112>__Added
issclaim by @fabianbadoi inGHSA-75c5-xw7c-p5pm <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-75c5-xw7c-p5pm>__v2.11.0Compare Source
What's Changed
optionsin decode, decode_complete; Improve docs by @pachewise in #1045algorithm=Noneto "none" by @qqii in #1056PyJWKClient.get_signing_key_from_jwtannotation by @khvn26 in #1048floatinstead ofintforlifespanandtimeoutby @nikitagashkov in #1068SyntaxWarningcaused by invalid escape sequences by @kurtmckee in #1103pep517, which is deprecated, tobuildby @kurtmckee in #1108New Contributors
Full Changelog: jpadilla/pyjwt@2.10.1...2.11.0
v2.10.1Compare Source
Fixed
issclaim. Thanks @fabianbadoi! (See: GHSA-75c5-xw7c-p5pm)Full Changelog: jpadilla/pyjwt@2.10.0...2.10.1
v2.10.0Compare Source
Changed
#​910 <https://github.com/jpadilla/pyjwt/pull/910>__#​913 <https://github.com/jpadilla/pyjwt/pull/913>__Fixed
#​910 <https://github.com/jpadilla/pyjwt/pull/910>__is_ssh_key+ add unit test by @bdraco in#​940 <https://github.com/jpadilla/pyjwt/pull/940>__jwt.decode()to accept a PyJWK object by @luhn in#​886 <https://github.com/jpadilla/pyjwt/pull/886>__algorithm_nameattribute available on PyJWK by @luhn in#​886 <https://github.com/jpadilla/pyjwt/pull/886>__InvalidKeyErroron invalid PEM keys to be compatible with cryptography 42.x.x by @CollinEMac in#​952 <https://github.com/jpadilla/pyjwt/pull/952>__<https://github.com/jpadilla/pyjwt/pull/963>__v2.9.0Compare Source
Changed
#​910 <https://github.com/jpadilla/pyjwt/pull/910>__#​913 <https://github.com/jpadilla/pyjwt/pull/913>__Fixed
#​910 <https://github.com/jpadilla/pyjwt/pull/910>__is_ssh_key+ add unit test by @bdraco in#​940 <https://github.com/jpadilla/pyjwt/pull/940>__jwt.decode()to accept a PyJWK object by @luhn in#​886 <https://github.com/jpadilla/pyjwt/pull/886>__algorithm_nameattribute available on PyJWK by @luhn in#​886 <https://github.com/jpadilla/pyjwt/pull/886>__InvalidKeyErroron invalid PEM keys to be compatible with cryptography 42.x.x by @CollinEMac in#​952 <https://github.com/jpadilla/pyjwt/pull/952>__<https://github.com/jpadilla/pyjwt/pull/963>__v2.8.0Compare Source
Changed
#​809 <https://github.com/jpadilla/pyjwt/pull/809>__#​846 <https://github.com/jpadilla/pyjwt/pull/846>__Algorithman abstract base class by @Viicos in#​845 <https://github.com/jpadilla/pyjwt/pull/845>__#​863 <https://github.com/jpadilla/pyjwt/pull/863>__Fixed
compute_hash_digestas a method ofAlgorithmobjects, which usesthe underlying hash algorithm to compute a digest. If there is no appropriate
hash algorithm, a
NotImplementedErrorwill be raised in#​775 <https://github.com/jpadilla/pyjwt/pull/775>__headersargument toPyJWKClient. If provided, the headerswill be included in requests that the client uses when fetching the JWK set by @thundercat1 in
#​823 <https://github.com/jpadilla/pyjwt/pull/823>__#​829 <https://github.com/jpadilla/pyjwt/pull/829>__sort_headersparameter toapi_jwt.encodeby @evroon in#​832 <https://github.com/jpadilla/pyjwt/pull/832>__#​830 <https://github.com/jpadilla/pyjwt/pull/830>__#​843 <https://github.com/jpadilla/pyjwt/pull/843>__#​875 <https://github.com/jpadilla/pyjwt/pull/875>__#​876 <https://github.com/jpadilla/pyjwt/pull/876>__#​873 <https://github.com/jpadilla/pyjwt/pull/873>__as_dictoption toAlgorithm.to_jwkby @fluxth in#​881 <https://github.com/jpadilla/pyjwt/pull/881>__v2.7.0Compare Source
Changed
#​809 <https://github.com/jpadilla/pyjwt/pull/809>__#​846 <https://github.com/jpadilla/pyjwt/pull/846>__Algorithman abstract base class by @Viicos in#​845 <https://github.com/jpadilla/pyjwt/pull/845>__#​863 <https://github.com/jpadilla/pyjwt/pull/863>__Fixed
compute_hash_digestas a method ofAlgorithmobjects, which usesthe underlying hash algorithm to compute a digest. If there is no appropriate
hash algorithm, a
NotImplementedErrorwill be raised in#​775 <https://github.com/jpadilla/pyjwt/pull/775>__headersargument toPyJWKClient. If provided, the headerswill be included in requests that the client uses when fetching the JWK set by @thundercat1 in
#​823 <https://github.com/jpadilla/pyjwt/pull/823>__