VDB
GCVE-VVD-MAGEIA-2024-238
GCVE-VVD-MAGEIA-2024-238
Advisory Published
Authlib before 1.3.1 has algorithm confusion with asymmetric public
keys. Unless an algorithm is specified in a jwt.decode call, HMAC
verification is allowed with any asymmetric public key. (This is similar
to CVE-2022-29217 and CVE-2024-33663.)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | guayadeque | 0 (affected), 0.6.2-1.mga9 (unaffected) | — |
| Mageia | python-authlib | 0 (affected), 1.3.1-1.mga9 (unaffected) | — |
Aliases
Transitive aliases
References
Updated guayadeque packages fix bugs
advisory
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.