CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-45768

highCVSS 7covered by 1 sourcefirst seen 2026-08-06

CSIRTS triage

vendor: PyJWTproduct: PyJWTOtheraffected: 2.10.1
What
The library uses weak encryption when configured with short key lengths, though key length selection is delegated to the application.
Who is affected
Applications using PyJWT 2.10.1 with insufficient key lengths are affected.
Urgency
Moderate; not exploited and disputed by supplier as application-level configuration issue, but users may benefit from stronger defaults.
Action
Review key length configuration in applications using PyJWT and consider upgrading to a version with enforced minimum key length or explicit warnings.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-45768

Get an email if CVE-2025-45768 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-45768

CVE.org record

Embed the live status

CVE-2025-45768 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-45768 status](https://www.csirts.com/badge/CVE-2025-45768)](https://www.csirts.com/cve/CVE-2025-45768)