CVE-2025-45770 Affecting py3.11-jwt package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-PY311JWT-14104329
  • published25 Nov 2025
  • disclosed31 Jul 2025

Introduced: 31 Jul 2025

CVE-2025-45770  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest py3.11-jwt.

NVD Description

Note: Versions mentioned in the description apply only to the upstream py3.11-jwt package and not the py3.11-jwt package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.