Debian Package Tracker
Register | Log in
Subscribe

joserfc

Python library for JSON Object Signing and Encryption (JOSE)

Choose email to subscribe with

general
  • source: joserfc (main)
  • version: 1.6.1-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Edward Betts [DMD]
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 1.1.0-1
  • testing: 1.6.1-1
  • unstable: 1.6.1-1
versioned links
  • 1.1.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-joserfc
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-65015: joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Python logging to record an arbitrarily large, forged JWT payload. In situations where a misconfigured — or entirely absent — production-grade web server sits in front of a Python web application, an attacker may be able to send arbitrarily large bearer tokens in the HTTP request headers. When this occurs, Python logging or diagnostic tools (e.g., Sentry) may end up processing extremely large log messages containing the full JWT header during the joserfc.jwt.decode() operation. The same behavior also appears when validating claims and signature payload sizes, as the library raises joserfc.errors.ExceededSizeError() with the full payload embedded in the exception message. Since the payload is already fully loaded into memory at this stage, the library cannot prevent or reject it. This issue has been patched in versions 1.3.5 and 1.4.2.
Created: 2025-11-19 Last update: 2026-01-03 07:30
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-01-01 Last update: 2026-01-01 07:00
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2026-01-01 Last update: 2026-01-01 11:33
news
[rss feed]
  • [2026-01-03] joserfc 1.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-31] Accepted joserfc 1.6.1-1 (source) into unstable (Edward Betts)
  • [2025-12-18] joserfc 1.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-15] Accepted joserfc 1.6.0-1 (source) into unstable (Edward Betts)
  • [2025-12-05] joserfc 1.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-03] Accepted joserfc 1.5.0-1 (source) into unstable (Edward Betts)
  • [2025-11-22] joserfc 1.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-19] Accepted joserfc 1.4.3-1 (source) into unstable (Edward Betts)
  • [2025-11-09] joserfc 1.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-07] Accepted joserfc 1.4.1-1 (source) into unstable (Edward Betts)
  • [2025-10-12] joserfc 1.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-10] Accepted joserfc 1.4.0-1 (source) into unstable (Edward Betts)
  • [2025-09-26] joserfc 1.3.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-24] Accepted joserfc 1.3.4-1 (source) into unstable (Edward Betts)
  • [2025-09-10] joserfc 1.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-06] Accepted joserfc 1.3.2-1 (source) into unstable (Edward Betts)
  • [2025-09-01] joserfc 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-28] Accepted joserfc 1.3.1-1 (source) into unstable (Edward Betts)
  • [2025-08-13] joserfc 1.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-31] Accepted joserfc 1.2.2-1 (source) into unstable (Edward Betts)
  • [2025-07-09] Accepted joserfc 1.2.0-1 (source) into unstable (Edward Betts)
  • [2025-06-19] joserfc 1.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-30] Accepted joserfc 1.1.0-1 (source) into unstable (Edward Betts)
  • [2025-03-09] joserfc 1.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-06] Accepted joserfc 1.0.4-1 (source) into unstable (Edward Betts)
  • [2025-02-15] joserfc 1.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-12] Accepted joserfc 1.0.3-1 (source) into unstable (Edward Betts)
  • [2025-01-28] joserfc 1.0.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-24] Accepted joserfc 1.0.2-1 (source) into unstable (Edward Betts)
  • [2024-12-10] joserfc 1.0.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (-, 33)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.5.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing