Executive brief
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Affected products
- PyPI python-jose
CVE identifiers
- CVE-2026-85394
- CVE-2024-33663
Junglewise Threat Intelligence
CVE-2026-85394 · Severity: low · CVSS 3.1 · Published 2024-04-26
Technologies: python-jose (PyPI). Vendors: PyPI.
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.